ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
ZDI discloses CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvBitBlt improper object management flaw allowing local attackers to escalate privileges.
ZDI advisory ZDI-26-542 describes improper object management in Microsoft Windows' UMPDDrvBitBlt function, tracked as CVE-2026-62712 with a CVSS score of 7.8. The flaw allows local attackers to escalate privileges on affected Windows installations. Exploitation requires first obtaining the ability to execute low-privileged code on the target system.
- CVE-2026-62712: improper object management in Windows UMPDDrvBitBlt
- CVSS 7.8 local privilege escalation
- Requires prior low-privileged code execution on target
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-62712 | Heap Buffer Overflow in Windows Win32K Enables Local Privilege Escalation CVE-2026-62712 is a heap-based buffer overflow (CWE-122) in the Windows Win32K kernel component, with Microsoft's related advisories (ZDI-26-542/618/619/620/621) tying the flaw to user-mode printer driver (UMPD) graphics callbacks such as UMPDDrvBitBlt, UMPDDrvStretchBlt and UMPDDrvRealizeBrush. A local attacker with valid low-privileged credentials can trigger the overflow through crafted GDI/printer-driver operations, with no user interaction required. Successful exploitation elevates the attacker from a standard user to kernel/SYSTEM level, yielding high confidentiality, integrity and availability impact on the host. Every Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server (2012, 2016, 2019, 2022) installation on the listed builds is affected, which spans most of the supported Windows fleet. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.4%, indicating no confirmed exploitation to date. Do: Apply the patch for CVE-2026-62712 from Microsoft's security update on all listed Windows 10, Windows 11 and Windows Server builds, prioritizing multi-user systems such as RDS hosts and print servers where untrusted users can execute code. Until patched, restrict interactive logon rights on servers to trusted users, since a kernel win32k overflow of this type has no reliable workaround. Verify remediation against the build numbers listed in Microsoft's advisory rather than assuming a single KB applies to every branch. | 7.8 | <1% |
| mass≈1 billion+ Windows installations (every unpatched install of the listed Windows 10/11/Server builds is affected) |
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
This source does not provide full text. Read it at zerodayinitiative.com.