ZeroHour

CVE-2026-12518

mass

Local Privilege Escalation to SYSTEM in Logitech Logi Options+ Updater on Windows

CVSS 4.0
8.5 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-12518 is an improper privilege management flaw (CWE-269) in the Logitech Logi Options+ updater service on Windows, which runs with SYSTEM privileges. A low-privileged local user can abuse the service to execute arbitrary code in the SYSTEM context, fully compromising the machine. Exploitation requires an attacker to already have local access or code execution as an unprivileged user on a victim's workstation, which is typical of how commodity malware and malicious insiders chain elevation bugs rather than a remotely reachable flaw. Any Windows machine running the Logi Options+ software and its updater service is affected, spanning both consumer and enterprise environments given Logitech's dominance in mice and keyboards. The vulnerability is rated high (CVSS 4.0: 8.5), but no public proof-of-concept exists, it is not in CISA's KEV catalog, and no exploitation has been reported to date.

What to do: Update Logi Options+ to the latest version as soon as Logitech releases a patched build, since no fixed version number is specified in the advisory data — check Logitech's official security advisory and the in-app updater. In the interim, the risk is limited to attackers with local access or malware already running as an unprivileged user, so prioritize shared/multi-user workstations, enforce least-privilege local accounts, and monitor for suspicious processes spawning from or modifying the Logi Options+ updater service. Asset teams should inventory endpoints running Logi Options+ to scope remediation.

Affected
Logitech Logi Options+ (Windows, updater service)
Estimated exposure
massTens of millions of Windows endpoints (order of magnitude ≈10M+ installations) — Logitech is the leading PC peripherals vendor and Logi Options+ is the required companion software for its popular MX, Signature, and ergonomic device lines, with downloads and active installs plausibly in the tens of millions across…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

Weakness
CWE-269
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.