Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-69844Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
An out-of-bounds read vulnerability in Windows Win32K allows a local user with logon access to elevate privileges to system level. The vulnerability affects Windows 10 (all versions including 1607, 1809, 21H2, 22H2), Windows 11 (all versions including 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on 32-bit, x64-based, and ARM64-based systems. Exploitation requires an attacker to already have a user account and the ability to execute code on the local system.
What this means
What could happen
A user with local logon access could exploit an out-of-bounds read in Win32K to gain system-level privileges on a Windows computer, potentially allowing them to modify critical settings or access sensitive data on that machine.
Who's at risk
Windows system administrators managing Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025. This affects all editions and architectures of these operating systems. Utilities using Windows-based HMIs (human-machine interfaces), engineering workstations, and domain-joined computers in control network environments should prioritize patching.
How it could be exploited
An attacker with an active user account on the Windows system could run a specially crafted application that triggers the out-of-bounds read in the Win32K kernel component. If successful, the attacker gains elevated system privileges without needing to be an administrator. This is a local-only attack—the attacker must already have login access to the computer.
Prerequisites
- Local user account on the affected Windows system
- Ability to execute code as that local user
Requires local user account access (not remotely exploitable)Low attack complexityAffects Windows systems across multiple versions and architectures
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/2
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2025
HOTFIXApply the September 2026 Windows security update to bring your systems to the patched build versions (e.g., Build 10.0.19045.7725 for Windows 10 22H2, Build 10.0.22631.7582 for Windows 11 23H2, Build 10.0.26100.33438 for Windows Server 2025)
Long-term hardening
0/1HARDENINGReview and restrict local user accounts—disable or remove accounts that do not have a legitimate business purpose, particularly on domain-joined machines or those handling operational data
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8f98715c-a4ee-457e-803a-fdf3f0b0650aGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.