CVE-2026-62737
Windows Kernel Elevation of Privilege Vulnerability
Description
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62737 is a Windows bug that could let a local attacker gain full system privileges; if your business computers are reachable only through normal user logins, it’s still worth patching because Windows 11 and Windows Server 2025 are affected.
CVE-2026-62737 is a local Windows kernel privilege escalation (CWE-822) caused by an untrusted pointer dereference in kernel code; a person/process with authorized local access could trigger the flaw to elevate privileges.
What to do now
- Check whether you run Windows 11 or Windows Server 2025 and what exact build/version you are on.
- Compare your build to Microsoft’s fixed builds for CVE-2026-62737 (Windows 11: 10.0.26100.9106 / 10.0.26200.9106 / 10.0.28000.2704 / 10.0.26100.9168 / 10.0.26200.9168; Windows Server 2025: 10.0.26100.33222 / 10.0.26100.33296).
- Install the Microsoft security update for CVE-2026-62737 from the MSRC update guide.
- Re-check the machine build/version after patching and confirm Windows Update reports the update is installed.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
References
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)en-us·Help Net Security· Exploited Windows Lazarus Group
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62737 and every CVE in our database. Create a free account — no credit card required.
Create Free Account