Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69779Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A time-of-check time-of-use (TOCTOU) race condition in Windows Win32K kernel allows a standard user with local access to escalate privileges to system level. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 across 32-bit, x64-based, and ARM64-based architectures. Exploitation requires the attacker to already have a user account and local code execution capability, but no administrator credentials are needed. Microsoft has released patches for all affected versions.

What this means
What could happen
A logged-in user with standard privileges could gain system-level access to a Windows server or workstation, potentially allowing them to modify SCADA client software, HMI applications, or local control logic. This could compromise the integrity of operational data or control commands sent to field devices.
Who's at risk
IT and OT teams operating Windows-based SCADA workstations, HMI servers, engineering stations, or supervisory control systems running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. This includes any Windows system used for process monitoring, data historian access, or issuing control commands to industrial equipment.
How it could be exploited
An attacker with a standard user account on a Windows system exploits a race condition in the Win32k kernel subsystem to escalate privileges from user to system level. This requires local code execution and the ability to time the attack against a kernel operation, but no additional authentication or network access is needed once inside the system.
Prerequisites
  • Local user account (standard user, not administrator)
  • Ability to execute code on the target Windows system
  • Physical or RDP/remote access to the system
Low-complexity local exploitationAffects operational control systems if running WindowsNo network access required—only local user account neededHigh privilege impact (system-level access on control workstations)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/1
HARDENINGRestrict local access to SCADA workstations, HMI servers, and engineering systems—limit who can log in with standard user accounts
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all affected Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/2
HARDENINGEnforce multi-factor authentication or strong password policies for all local accounts on operational control systems
HARDENINGMonitor and audit local user account creation and privilege escalation attempts on critical Windows systems
API: /api/v1/advisories/33e71173-47fe-4fe4-a973-7ac373b05494

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.