CVE-2026-62728
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Description
Time-of-check time-of-use (toctou) race condition in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62728 is a Windows local security bug that lets a normal logged-in user exploit a timing flaw to gain administrator control; if your business has Windows machines with standard user accounts, you should patch.
CVE-2026-62728 is a local privilege escalation due to a time-of-check time-of-use (TOCTOU) race condition in the Windows Common Log File System Driver, where an attacker with a low-privilege account can change a file between the driver’s checks and later use to trick it into granting higher-level access.
What to do now
- Check which of these are installed and their OS version: Windows 10, Windows 11, Windows Server 2012, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025.
- Verify whether the machine is already updated past these fixed build numbers for your specific Windows version.
- Install the Microsoft security update for CVE-2026-62728 from the MSRC update guide.
- If you can’t patch immediately, restrict or remove low-privilege accounts that are able to log on to the affected systems, and monitor for unusual privilege changes and suspicious activity around file system actions by non-admin users.
CVSS Vector Breakdown
AV:LAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62728 and every CVE in our database. Create a free account — no credit card required.
Create Free Account