Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-69818Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
A use-after-free vulnerability in the Windows Win32k kernel component allows a user with a local account to elevate their privileges to system level. This affects Windows Server 2025 and Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures. The vulnerability requires interactive local access and does not appear to be actively exploited in the wild.
What this means
What could happen
A user with local login access to a Windows server or workstation could exploit a memory flaw to run commands with higher privileges, potentially gaining control of the device and any OT software running on it.
Who's at risk
IT administrators and OT operators who manage Windows Server 2025 or Windows 11 systems (especially those running SCADA clients, data historians, or engineering workstations in water/power utilities). The vulnerability requires local access, so it poses the highest risk on shared engineering workstations or systems where multiple staff have login credentials.
How it could be exploited
An attacker with a local user account on an affected Windows system could trigger a use-after-free condition in the Win32k kernel component to elevate their privileges to system level, then execute arbitrary code with elevated permissions.
Prerequisites
- Local user account on the Windows system
- Interactive login access or the ability to run local code as that user
- Windows Server 2025, Windows 11 24H2, 25H2, or 26H1 (unpatched)
Low complexity attackLocal access only (not remotely exploitable)Requires valid user credentials
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/4Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 11 Version 24H2 (x64 or ARM64) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (x64 or ARM64) to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64 or ARM64) to Build 10.0.28000.2954 or later
Long-term hardening
0/2HARDENINGRestrict local interactive login access to Windows servers and engineering workstations to authorized personnel only
HARDENINGDisable unnecessary local user accounts and enforce strong password policies
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/4e1fea9e-2cea-4275-ae7b-d3cf54b03391Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.