Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-69818Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A use-after-free vulnerability in the Windows Win32k kernel component allows a user with a local account to elevate their privileges to system level. This affects Windows Server 2025 and Windows 11 versions 24H2, 25H2, and 26H1 on both x64 and ARM64 architectures. The vulnerability requires interactive local access and does not appear to be actively exploited in the wild.

What this means
What could happen
A user with local login access to a Windows server or workstation could exploit a memory flaw to run commands with higher privileges, potentially gaining control of the device and any OT software running on it.
Who's at risk
IT administrators and OT operators who manage Windows Server 2025 or Windows 11 systems (especially those running SCADA clients, data historians, or engineering workstations in water/power utilities). The vulnerability requires local access, so it poses the highest risk on shared engineering workstations or systems where multiple staff have login credentials.
How it could be exploited
An attacker with a local user account on an affected Windows system could trigger a use-after-free condition in the Win32k kernel component to elevate their privileges to system level, then execute arbitrary code with elevated permissions.
Prerequisites
  • Local user account on the Windows system
  • Interactive login access or the ability to run local code as that user
  • Windows Server 2025, Windows 11 24H2, 25H2, or 26H1 (unpatched)
Low complexity attackLocal access only (not remotely exploitable)Requires valid user credentials
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33438
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.9445
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.9445
Windows Server 2025All versionsBuild 10.0.26100.33438
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2954
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2954
Remediation & Mitigation
0/6
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.33438 or later
All products
HOTFIXUpdate Windows 11 Version 24H2 (x64 or ARM64) to Build 10.0.26100.9445 or later
HOTFIXUpdate Windows 11 Version 25H2 (x64 or ARM64) to Build 10.0.26200.9445 or later
HOTFIXUpdate Windows 11 Version 26H1 (x64 or ARM64) to Build 10.0.28000.2954 or later
Long-term hardening
0/2
HARDENINGRestrict local interactive login access to Windows servers and engineering workstations to authorized personnel only
HARDENINGDisable unnecessary local user accounts and enforce strong password policies
API: /api/v1/advisories/4e1fea9e-2cea-4275-ae7b-d3cf54b03391

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7 - OTPulse