ZeroHour
ZDI Published Advisoriespublished ()ingested 1
Part of a story covered by 4 sources: “ZDI details four Windows UMPD improper object management flaws (ZDI-26-618, ZDI-26-619, ZDI-26-620, ZDI-26-621) sharing CVE-2026-62712, each rated CVSS 7.8 for local privilege…” — merged summary and timeline →

ZDI-26-618: Microsoft Windows UMPDDrvStretchBlt Improper Object Management Local Privilege Escalation Vulnerability

mediumVulnerabilityimportance 38CVE-2026-62712
AI summary · glm-5.3-flash

ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvStretchBlt improper object-management flaw enabling local privilege escalation.

Zero Day Initiative advisory ZDI-26-618 describes an improper object management issue in Microsoft Windows' UMPDDrvStretchBlt component. A local attacker who can already execute low-privileged code on the system can escalate privileges. The flaw carries a CVSS 3.0 rating of 7.8; details on affected versions and patch availability are limited in the advisory.

  • Local privilege escalation in Windows UMPDDrvStretchBlt component
  • CVSS 3.0 score of 7.8 assigned by ZDI
  • Exploitation requires prior execution of low-privileged code

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-62712
Heap Buffer Overflow in Windows Win32K Enables Local Privilege Escalation

CVE-2026-62712 is a heap-based buffer overflow (CWE-122) in the Windows Win32K kernel component, with Microsoft's related advisories (ZDI-26-542/618/619/620/621) tying the flaw to user-mode printer driver (UMPD) graphics callbacks such as UMPDDrvBitBlt, UMPDDrvStretchBlt and UMPDDrvRealizeBrush. A local attacker with valid low-privileged credentials can trigger the overflow through crafted GDI/printer-driver operations, with no user interaction required. Successful exploitation elevates the attacker from a standard user to kernel/SYSTEM level, yielding high confidentiality, integrity and availability impact on the host. Every Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server (2012, 2016, 2019, 2022) installation on the listed builds is affected, which spans most of the supported Windows fleet. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.4%, indicating no confirmed exploitation to date.

Do: Apply the patch for CVE-2026-62712 from Microsoft's security update on all listed Windows 10, Windows 11 and Windows Server builds, prioritizing multi-user systems such as RDS hosts and print servers where untrusted users can execute code. Until patched, restrict interactive logon rights on servers to trusted users, since a kernel win32k overflow of this type has no reliable workaround. Verify remediation against the build numbers listed in Microsoft's advisory rather than assuming a single KB applies to every branch.

7.8<1%
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012, 2016, 2019, 2022
mass≈1 billion+ Windows installations (every unpatched install of the listed Windows 10/11/Server builds is affected)
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.

This source does not provide full text. Read it at zerodayinitiative.com.