Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7CVE-2026-70283Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary
Incorrect authorization in Windows Win32K allows a local attacker to elevate privileges. An authorized user with standard account access to the system could escalate to system level without administrator intervention. This affects Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 editions.
What this means
What could happen
A local attacker with a standard user account could escalate privileges to system level, allowing them to run arbitrary commands with administrative rights on your servers and workstations.
Who's at risk
Windows 10 and Windows 11 client systems, Windows Server 2016, 2019, 2022, and 2025, affecting both standard and Server Core installations. Any operator workstation or server on your network running these OS versions is at risk, particularly if used for engineering, SCADA workstations, or remote OT access.
How it could be exploited
An attacker with login access to a Windows system (via compromised credentials, physical access, or initial breach) could trigger a kernel-level authorization flaw in Win32k to elevate from user-level to system-level privileges without administrator approval.
Prerequisites
- Local user account with interactive logon access to the Windows system
- No additional privileged credentials or administrative rights needed at time of exploitation
Local exploitation only (requires initial access)Low EPSS score (0.2%)Requires standard user privileges
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/2HARDENINGRestrict local interactive logon access to trusted administrators only via Group Policy or access controls
HARDENINGDisable or restrict remote desktop access to only necessary systems and use network segmentation to limit exposure
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXPrioritize patching servers running Windows Server 2016, 2019, 2022, and 2025 first
All products
HOTFIXApply the September 2026 Windows security update to all affected Windows versions
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/87d0a462-e92e-4a0b-a6ec-7f18827b2ee7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.