CVE-2026-62712
Windows Win32k Elevation of Privilege Vulnerability
Description
Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62712 is a Windows flaw where a local (already-signed-in) user can trigger the graphics kernel to gain administrator-level access, so you should patch quickly on affected Windows systems even though there’s no confirmed public real-world incident yet.
Windows Win32k local privilege escalation (CWE-122) where an authenticated local user can exploit a memory/heap error in the graphics-related kernel component by sending excessively large data to a specific function, resulting in administrator-level command execution.
What to do now
- Check whether your Windows 10/11 or Windows Server (2012–2025) devices are on a version that still needs the CVE fixes listed by Microsoft.
- For Windows 10, upgrade to one of the fixed builds: 10.0.14393.9418, 10.0.17763.9121, 10.0.19044.7663, or 10.0.19045.7663.
- For Windows 11, upgrade to one of the fixed builds: 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, or 10.0.28000.2704.
- For Windows Server, upgrade to the fixed builds: 6.2.9200.26280 (2012), 6.3.9600.23338 (2012 R2), 10.0.14393.9418 (2016), 10.0.17763.9121 (2019), and 10.0.??? (2022/2025 not listed in provided findings).
- If you can’t patch immediately, restrict who can log on to the affected Windows machines (reduce local accounts/users), and treat any untrusted local user as an urgent risk until updates are applied.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62712 and every CVE in our database. Create a free account — no credit card required.
Create Free Account