Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued fixes for CVE-2026-69324: Windows Performance Monitor Elevation of Privilege Vulnerability, an Important Windows security flaw that could let an authorized local attacker obtain SYSTEM privileges—the highest standard privilege level on a Windows machine.

Microsoft describes the issue as: “Access of resource using incompatible type ('type confusion') in Windows Performance Monitor allows an authorized attacker to elevate privileges locally.” The weakness is associated with CWE-125 and CWE-843.

Abstract illustration of connected devices separated by a protected security boundary. Security assessment​

  • Title: Windows Performance Monitor Elevation of Privilege Vulnerability
  • Severity: Important
  • CVSS base score: 7.8
  • CVSS temporal score: 6.8
  • CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • Weaknesses: CWE-125, CWE-843
  • Publicly disclosed: No
  • Exploited: No
  • Customer action required: Yes
  • Exploitation assessment: Exploitation Less Likely

The CVSS vector reflects a local attack scenario with low attack complexity and low privileges required, without user interaction. Successful exploitation can affect the confidentiality, integrity, and availability of the affected device at a high level.

Microsoft’s advisory is blunt about the potential outcome: “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” Put plainly, this is not a remote break-in vulnerability, but it matters greatly after an attacker—or malicious software—already has a foothold on a PC or server. Privilege-escalation bugs are the elevator in an intrusion: getting into the lobby is bad; reaching the penthouse is worse.

What administrators should do​

Install the applicable Microsoft update and verify the device reaches the listed fixed build. Organizations should prioritize systems where standard users can execute untrusted or lightly vetted software, including shared workstations, virtual desktop deployments, developer machines, jump hosts, and servers with multiple administrative roles.

Windows client updates​

Affected productUpdateVendor fixed version/build
Windows 10 Version 1607 for 32-bit Systems (x86)KB512309910.0.14393.9512
Windows 10 Version 1607 for x64-based SystemsKB512309910.0.14393.9512
Windows 10 Version 1809 for 32-bit Systems (x86)KB512287610.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsKB512287610.0.17763.9245
Windows 10 Version 21H2 for 32-bit Systems (x86)KB512287810.0.19044.7725
Windows 10 Version 21H2 for ARM64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 21H2 for x64-based SystemsKB512287810.0.19044.7725
Windows 10 Version 22H2 for 32-bit Systems (x86)KB512287810.0.19045.7725
Windows 10 Version 22H2 for ARM64-based SystemsKB512287810.0.19045.7725
Windows 10 Version 22H2 for x64-based SystemsKB512287810.0.19045.7725
Windows 11 Version 23H2 for ARM64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 23H2 for x64-based SystemsKB512288010.0.22631.7582
Windows 11 Version 24H2 for ARM64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 24H2 for x64-based SystemsKB512400810.0.26100.9445
Windows 11 Version 25H2 for ARM64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 25H2 for x64-based SystemsKB512400810.0.26200.9445
Windows 11 Version 26H1 for ARM64-based SystemsKB512401210.0.28000.2954
Windows 11 version 26H1 for x64-based SystemsKB512401210.0.28000.2954

Remediation values:

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server updates​

Affected productUpdateVendor fixed version/build
Windows Server 2012 (Server Core installation) (x64)KB51230656.2.9200.26349
Windows Server 2012 (x64)KB51230656.2.9200.26349
Windows Server 2012 R2 (Server Core installation) (x64)KB51230666.3.9600.23398
Windows Server 2012 R2 (x64)KB51230666.3.9600.23398
Windows Server 2016 (Server Core installation) (x64)KB512309910.0.14393.9512
Windows Server 2016 (x64)KB512309910.0.14393.9512
Windows Server 2019 (Server Core installation) (x64)KB512287610.0.17763.9245
Windows Server 2019 (x64)KB512287610.0.17763.9245
Windows Server 2022 (Server Core installation) (x64)KB512288210.0.20348.5622
Windows Server 2022 (x64)KB512288210.0.20348.5622
Windows Server 2025 (Server Core installation) (x64)KB512287110.0.26100.33438
Windows Server 2025 (x64)KB512287110.0.26100.33438

Remediation values:

  • For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

For patch-management teams, the practical task is straightforward: deploy the applicable cumulative update, restart where required by the update process, and confirm the reported OS build matches the fixed build for that product and architecture. This is a broad client-and-server fix set, so inventory accuracy matters; a correct KB for one Windows release is not necessarily the correct KB for its neighbor.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com