Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released fixes for CVE-2026-69844, Windows Win32k Elevation of Privilege Vulnerability, an Important-rated local privilege-escalation flaw affecting a broad range of supported Windows client and server releases.

The vulnerability is an out-of-bounds read in Windows Win32K. Microsoft’s description states: “Out-of-bounds read in Windows Win32K allows an authorized attacker to elevate privileges locally.” The weakness is classified as CWE-125.

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges, according to Microsoft’s advisory. That is the Windows equivalent of being handed the master keyring: an attacker who already has authorized local access could potentially take control of the affected machine at its highest privilege level.

Severity and Microsoft assessment​

FieldValue
CVECVE-2026-69844
TitleWindows Win32k Elevation of Privilege Vulnerability
SeverityImportant
CVSS base score7.8
CVSS temporal score6.8
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
WeaknessCWE-125
Publicly disclosed: No
Exploited: No
Exploitation assessmentExploitation Unlikely
Customer action required: Yes

The CVSS vector describes a vulnerability that requires local access and low privileges, but does not require user interaction. Its potential impact spans confidentiality, integrity, and availability. In practical administrative terms, this is a patch-priority issue for endpoints and servers where untrusted or lower-privileged users, applications, or workloads can obtain a foothold.

Affected Windows versions and fixed builds​

Microsoft maps CVE-2026-69844 to the following cumulative updates and fixed builds.

Windows 10​

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

Windows 11​

  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server​

  • For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

What administrators should do​

Deploy the applicable cumulative update through the organization’s normal Windows servicing process, then verify that devices report the mapped fixed build. Prioritize systems used by multiple people, exposed application servers, remote-access hosts, and devices where lower-privileged accounts may run code.

CVE-2026-69844 is a reminder that “local” does not mean “low consequence.” Once an attacker has any legitimate foothold, elevation-of-privilege bugs can turn a limited compromise into full SYSTEM control. The sensible response is decidedly unglamorous—and highly effective: install the appropriate KB, confirm the build, and keep Windows patch compliance from becoming the weak link.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com