CVE-2026-62832
Windows User Profile Service Elevation of Privilege Vulnerability
Description
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-62832 is a Windows local privilege-upgrade flaw in the User Profile Service; if your business uses Windows 10, Windows 11, Windows Server 2022, or Windows Server 2025, you should apply Microsoft’s update because attackers with local access may be able to gain higher privileges.
CVE-2026-62832 is a Windows User Profile Service elevation of privilege issue caused by improper link resolution before file access (“link following”); a locally authorized attacker (low privileges) can leverage this to increase privileges on Windows 10/11 and Windows Server 2022/2025.
What to do now
- Check your exact Windows version/build number on every affected device (Settings → System → About, or run
winver). - Upgrade Windows 10 to one of: 10.0.19044.7663 or 10.0.19045.7663.
- Upgrade Windows 11 to one of: 10.0.22631.7517, 10.0.26100.9168, 10.0.26200.9168, or 10.0.28000.2704.
- Upgrade Windows Server 2022 to 10.0.20348.5499 and Windows Server 2025 to 10.0.26100.33296.
- Re-check the version/build after patching to confirm every machine is on the fixed level.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft patches LegacyHive Windows zero-day vulnerabilityen-us·BleepingComputer· PoC Windows User Profile Service zero-day
- Nightmare Eclipse раскрыл 0-day-уязвимость ShieldBreak, которая затрагивает Microsoft Defenderru-ru·Хакер (xakep.ru)· PoC Microsoft Defender zero-day
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)en-us·Help Net Security· Exploited Windows Lazarus Group
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Accessen·The Hacker News· PoC Microsoft Defender privilege-escalation
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesen·Cisco Talos· Exploited Windows patch-tuesday
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft's Patch Tuesday Deluge Continues With August Updatesen·Dark Reading· Exploited Windows patch-tuesday
- Microsoft Plugs Nearly 400 Security Holesen-us·Krebs on Security· Exploited Windows patch-tuesday
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayen-us·SecurityWeek· Exploited Windows Lazarus group
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62832 and every CVE in our database. Create a free account — no credit card required.
Create Free Account