CVE-2026-12518
massLocal Privilege Escalation to SYSTEM in Logitech Logi Options+ Updater on Windows
CVE-2026-12518 is an improper privilege management flaw (CWE-269) in the Logitech Logi Options+ updater service on Windows, which runs with SYSTEM privileges. A low-privileged local user can abuse the service to execute arbitrary code in the SYSTEM context, fully compromising the machine. Exploitation requires an attacker to already have local access or code execution as an unprivileged user on a victim's workstation, which is typical of how commodity malware and malicious insiders chain elevation bugs rather than a remotely reachable flaw. Any Windows machine running the Logi Options+ software and its updater service is affected, spanning both consumer and enterprise environments given Logitech's dominance in mice and keyboards. The vulnerability is rated high (CVSS 4.0: 8.5), but no public proof-of-concept exists, it is not in CISA's KEV catalog, and no exploitation has been reported to date.
What to do: Update Logi Options+ to the latest version as soon as Logitech releases a patched build, since no fixed version number is specified in the advisory data — check Logitech's official security advisory and the in-app updater. In the interim, the risk is limited to attackers with local access or malware already running as an unprivileged user, so prioritize shared/multi-user workstations, enforce least-privilege local accounts, and monitor for suspicious processes spawning from or modifying the Logi Options+ updater service. Asset teams should inventory endpoints running Logi Options+ to scope remediation.
| Logitech Logi Options+ (Windows, updater service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
- Weakness
- CWE-269
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.