Elevation of Privilege Vulnerability in Windows User Profile Service by Microsoft
CVE-2026-62832

7.8HIGH

Key Information:

Badges

📰 News Worthy

What is CVE-2026-62832?

A vulnerability exists in the Windows User Profile Service that enables authorized attackers to leverage improper link resolution before file access. This flaw may allow attackers to gain elevated privileges locally, potentially leading to unauthorized access to sensitive data or system functionalities. Users and administrators should apply relevant patches and ensure operational security measures are in place.

Affected Version(s)

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7663

Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.7663

Windows 11 version 23H2 ARM64-based Systems 10.0.22631.0 < 10.0.22631.7517

News Articles

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by theregister

  • Vulnerability published

  • Vulnerability Reserved

.