Windows Win32K Security Feature Bypass Vulnerability

MonitorCVSS 4.7CVE-2026-69792Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A race condition vulnerability exists in Windows Win32K that allows an authorized local user to bypass a security feature. The vulnerability stems from concurrent execution using shared resources with improper synchronization. An attacker with local access could potentially exploit this to circumvent security protections. Microsoft has released patches for all supported Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 versions.

What this means
What could happen
An authorized local user could bypass a Windows security feature through a race condition in Win32K, potentially enabling privilege escalation or unauthorized access to protected resources.
Who's at risk
System administrators and IT staff responsible for Windows workstations and servers, particularly those running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025. This affects both general-purpose IT infrastructure and any OT systems (SCADA workstations, engineering stations, historian servers) that run on Windows platforms.
How it could be exploited
An attacker with local user account access to a Windows system could exploit a race condition in the Win32K kernel component by timing concurrent operations against shared resources. This could allow them to circumvent security feature protections that are normally enforced by the kernel.
Prerequisites
  • Local user account on the target Windows system
  • Ability to execute code or run applications locally
  • No network access required
Requires local user accessLow complexity exploitationSecurity feature bypassLow EPSS score (0.2%)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/12
Schedule — requires maintenance window
0/12

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXUpdate Windows Server 2016 to Build 10.0.14393.9512 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.9245 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5622 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 10 Version 1607 systems to Build 10.0.14393.9512 or later
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9245 or later
HOTFIXUpdate Windows 10 Version 21H2 systems to Build 10.0.19044.7725 or later
HOTFIXUpdate Windows 10 Version 22H2 systems to Build 10.0.19045.7725 or later
HOTFIXUpdate Windows 11 Version 23H2 systems to Build 10.0.22631.7582 or later
HOTFIXUpdate Windows 11 Version 24H2 systems to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 systems to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 26H1 systems to Build 10.0.28000.2954 or later
API: /api/v1/advisories/471a62f4-c836-449f-b24e-39a354f79883

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32K Security Feature Bypass Vulnerability | CVSS 4.7 - OTPulse