Windows Win32k Elevation of Privilege Vulnerability
Plan PatchCVSS 7.8CVE-2026-70289Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
Heap-based buffer overflow in the Windows Win32 Kernel Subsystem (Win32k) allows an authorized local user to elevate privileges. The vulnerability is in kernel-mode code and can be triggered by user-mode applications. Microsoft has released fixes for Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
A local attacker with user-level access could run arbitrary commands with elevated administrator privileges on Windows systems, allowing them to take full control of the machine including any OT applications running on it.
Who's at risk
Water authorities and utilities running Windows-based engineering workstations, HMI systems, data historians, or other control system components on Windows 10, Windows 11, Windows Server 2016/2019/2022/2025. This includes any OT network segments where staff log into Windows computers to perform control tasks.
How it could be exploited
An attacker must first have local access to the system as a regular user. They craft a malicious input that triggers a heap buffer overflow in the Windows Win32 kernel subsystem, causing it to execute code with system privileges, elevating their access from user to administrator.
Prerequisites
- Local user account on the affected Windows system
- Ability to run applications as the logged-in user
local exploitation onlyrequires valid user credentialsaffects safety-critical systems if HMI compromisedno authentication required after initial access
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply September 2026 Windows security update for your Windows version and architecture (10, 11, Server 2016, 2019, 2022, or 2025)
Long-term hardening
0/2HARDENINGReview and enforce principle of least privilege: remove administrative privileges from user accounts that do not require them
HARDENINGImplement application whitelisting to prevent unauthorized executables from running on engineering workstations and HMI systems
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/6cf4c439-6ed0-4717-b5b4-d69e77c2bd7dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.