Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7CVE-2026-70283Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

Incorrect authorization in Windows Win32K allows a local attacker to elevate privileges. An authorized user with standard account access to the system could escalate to system level without administrator intervention. This affects Windows 10, Windows 11, and Windows Server 2016, 2019, 2022, and 2025 editions.

What this means
What could happen
A local attacker with a standard user account could escalate privileges to system level, allowing them to run arbitrary commands with administrative rights on your servers and workstations.
Who's at risk
Windows 10 and Windows 11 client systems, Windows Server 2016, 2019, 2022, and 2025, affecting both standard and Server Core installations. Any operator workstation or server on your network running these OS versions is at risk, particularly if used for engineering, SCADA workstations, or remote OT access.
How it could be exploited
An attacker with login access to a Windows system (via compromised credentials, physical access, or initial breach) could trigger a kernel-level authorization flaw in Win32k to elevate from user-level to system-level privileges without administrator approval.
Prerequisites
  • Local user account with interactive logon access to the Windows system
  • No additional privileged credentials or administrative rights needed at time of exploitation
Local exploitation only (requires initial access)Low EPSS score (0.2%)Requires standard user privileges
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/4
Do now
0/2
HARDENINGRestrict local interactive logon access to trusted administrators only via Group Policy or access controls
HARDENINGDisable or restrict remote desktop access to only necessary systems and use network segmentation to limit exposure
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXPrioritize patching servers running Windows Server 2016, 2019, 2022, and 2025 first
All products
HOTFIXApply the September 2026 Windows security update to all affected Windows versions
API: /api/v1/advisories/87d0a462-e92e-4a0b-a6ec-7f18827b2ee7

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7 - OTPulse