Windows Win32k Elevation of Privilege Vulnerability

Plan PatchCVSS 7.8CVE-2026-70289Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

Heap-based buffer overflow in the Windows Win32 Kernel Subsystem (Win32k) allows an authorized local user to elevate privileges. The vulnerability is in kernel-mode code and can be triggered by user-mode applications. Microsoft has released fixes for Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
A local attacker with user-level access could run arbitrary commands with elevated administrator privileges on Windows systems, allowing them to take full control of the machine including any OT applications running on it.
Who's at risk
Water authorities and utilities running Windows-based engineering workstations, HMI systems, data historians, or other control system components on Windows 10, Windows 11, Windows Server 2016/2019/2022/2025. This includes any OT network segments where staff log into Windows computers to perform control tasks.
How it could be exploited
An attacker must first have local access to the system as a regular user. They craft a malicious input that triggers a heap buffer overflow in the Windows Win32 kernel subsystem, causing it to execute code with system privileges, elevating their access from user to administrator.
Prerequisites
  • Local user account on the affected Windows system
  • Ability to run applications as the logged-in user
local exploitation onlyrequires valid user credentialsaffects safety-critical systems if HMI compromisedno authentication required after initial access
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply September 2026 Windows security update for your Windows version and architecture (10, 11, Server 2016, 2019, 2022, or 2025)
Long-term hardening
0/2
HARDENINGReview and enforce principle of least privilege: remove administrative privileges from user accounts that do not require them
HARDENINGImplement application whitelisting to prevent unauthorized executables from running on engineering workstations and HMI systems
API: /api/v1/advisories/6cf4c439-6ed0-4717-b5b4-d69e77c2bd7d

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows Win32k Elevation of Privilege Vulnerability | CVSS 7.8 - OTPulse