Windows Kerberos Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-69822Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A numeric truncation error in Windows Kerberos allows an authorized local user to escalate their privileges to administrator level. The vulnerability affects Windows 10 (versions 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2019, Windows Server 2022, and Windows Server 2025. Microsoft has released patches for all affected versions.
What this means
What could happen
A user with local access to a Windows computer or server running Kerberos authentication could exploit a numeric error to gain elevated privileges, potentially allowing them to modify system settings, access sensitive data, or disrupt operations.
Who's at risk
This vulnerability affects Windows 10, Windows 11, and Windows Server systems used in utility control systems, engineering workstations, and data servers. Organizations running SCADA systems, HMI workstations, or Windows-based industrial controllers should prioritize patching systems that process or manage critical operational technology.
How it could be exploited
An attacker with a standard user account on a Windows 10, Windows 11, or Windows Server system can exploit a flaw in Kerberos numeric handling to escalate their privileges to administrator level. The attacker must already have the ability to log in locally to the machine.
Prerequisites
- Valid local user account on the affected Windows system
- Local logon access to the computer
- Windows Kerberos authentication enabled (standard default configuration)
Local access requiredLow complexity attackNo authentication bypass (existing user account needed)Affects system security foundation (Kerberos authentication)
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (21)
21 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXApply the 2026-Sep security update to Windows systems. For Windows 10 Version 1809, update to Build 10.0.17763.9245 or later; for Windows Server 2019, update to Build 10.0.17763.9245 or later; for Windows Server 2022, update to Build 10.0.20348.5622 or later; for Windows 10 Version 21H2, update to Build 10.0.19044.7725 or later; for Windows 10 Version 22H2, update to Build 10.0.19045.7725 or later; for Windows 11 Version 23H2, update to Build 10.0.22631.7582 or later; for Windows 11 Version 24H2, update to Build 10.0.26100.9445 or later; for Windows 11 Version 25H2, update to Build 10.0.26200.9445 or later; for Windows 11 Version 26H1, update to Build 10.0.28000.2954 or later; for Windows Server 2025, update to Build 10.0.26100.33438 or later.
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/160aad83-8cb6-4d54-95cb-b43967eca662Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.