ZeroHour

CVE-2026-62737

mass

Untrusted Pointer Dereference LPE in Windows 11 and Windows Server 2025 Kernel

CVSS 3.1
7.8 high
EPSS
3%p86
Published
()
Modified
AI analysis

CVE-2026-62737 is an untrusted pointer dereference (CWE-822) in the Windows Kernel, meaning the kernel dereferences a pointer influenced by untrusted input without adequate validation. A local, authenticated attacker with low privileges can trigger the flaw by running crafted code on the target machine, with no user interaction required. Successful exploitation results in elevation of privilege, allowing the attacker to move from their low-privileged context to kernel/SYSTEM-level control with high impact on confidentiality, integrity, and availability. Affected platforms are Windows 11 24H2, 25H2, and 26H1, and Windows Server 2025. There is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates roughly a 2.8% chance of exploitation within 30 days; it is not the zero-day reported under active attack in Microsoft's 400+ vulnerability release (CVE-2026-68820).

What to do: Install Microsoft's cumulative security update that fixes CVE-2026-62737 on Windows 11 24H2, 25H2, 26H1, and Windows Server 2025 (the specific KB/build is not provided in the source data; confirm remediation via update history or winver). Because exploitation requires local low-privileged code execution, prioritize hosts with interactive logons, RDP exposure, multi-user sessions, and VDI when sequencing the patch. When triaging Microsoft's large current release, patch the actively exploited zero-day (CVE-2026-68820) first, but apply this kernel privilege-escalation fix in the same update cycle.

Affected
Microsoft Windows 11 24H2
Microsoft Windows 11 25H2
Microsoft Windows 11 26H1
Microsoft Windows Server 2025
Estimated exposure
masson the order of 100M+ installations (Windows 11 24H2-and-later is the current mainstream Windows desktop baseline, plus Windows Server 2025 estates) — Windows runs on well over a billion devices worldwide and the 24H2/25H2/26H1 releases represent the bulk of current Windows 11 desktops alongside Windows Server 2025 deployments, so the estimate derives from OS market share and installed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-822
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

Microsoft's August 2026 Patch Tuesday fixes 400+ vulnerabilities, including an actively exploited Windows zero-day (CVE-2026-68820) used by North Korean attackers.

Microsoft's August 2026 Patch Tuesday fixes over 400 vulnerabilities, including CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver exploited in the wild by North Korean actors deploying a kernel-mode rootkit in Operation Dream Job. Critical unauthenticated remote code execution flaws in Microsoft QUIC (CVE-2026-62815) and Windows DNS (CVE-2026-62878) were also patched, alongside a SharePoint RCE chain combining CVE-2026-63520 with CVE-2026-55040. Researcher Nightmare-Eclipse released ShieldBreak, a PoC bypassing the July RoguePlanet Microsoft Defender patch (CVE-2026-50656), confirmed working by Will Dormann on Windows 11.

Help Net Security · Aug 12, 2026Exploit / PoC in the wildCVE-2026-68820CVE-2026-62832CVE-2026-72971+6 CVEs