ZDI-26-620: Microsoft Windows UMPDDrvPlgBlt Improper Object Management Local Privilege Escalation Vulnerability
ZDI disclosed CVE-2026-62712, a CVSS 7.8 Windows UMPDDrvPlgBlt improper object-management flaw enabling local privilege escalation.
Zero Day Initiative advisory ZDI-26-620 describes an improper object management flaw in Microsoft Windows' UMPDDrvPlgBlt component, sharing CVE-2026-62712 with the related UMPDDrvStretchBlt advisory. A local attacker able to run low-privileged code can escalate privileges on affected installations. The issue carries a CVSS 3.0 rating of 7.8.
- Local privilege escalation in Windows UMPDDrvPlgBlt component
- Shares CVE-2026-62712 with the related UMPDDrvStretchBlt advisory
- CVSS 3.0 score of 7.8 assigned by ZDI
- Exploitation requires prior execution of low-privileged code
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-62712 | Heap Buffer Overflow in Windows Win32K Enables Local Privilege Escalation CVE-2026-62712 is a heap-based buffer overflow (CWE-122) in the Windows Win32K kernel component, with Microsoft's related advisories (ZDI-26-542/618/619/620/621) tying the flaw to user-mode printer driver (UMPD) graphics callbacks such as UMPDDrvBitBlt, UMPDDrvStretchBlt and UMPDDrvRealizeBrush. A local attacker with valid low-privileged credentials can trigger the overflow through crafted GDI/printer-driver operations, with no user interaction required. Successful exploitation elevates the attacker from a standard user to kernel/SYSTEM level, yielding high confidentiality, integrity and availability impact on the host. Every Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2 through 26H1) and Windows Server (2012, 2016, 2019, 2022) installation on the listed builds is affected, which spans most of the supported Windows fleet. There is no public proof-of-concept, no CISA KEV listing, and a low EPSS of 0.4%, indicating no confirmed exploitation to date. Do: Apply the patch for CVE-2026-62712 from Microsoft's security update on all listed Windows 10, Windows 11 and Windows Server builds, prioritizing multi-user systems such as RDS hosts and print servers where untrusted users can execute code. Until patched, restrict interactive logon rights on servers to trusted users, since a kernel win32k overflow of this type has no reliable workaround. Verify remediation against the build numbers listed in Microsoft's advisory rather than assuming a single KB applies to every branch. | 7.8 | <1% |
| mass≈1 billion+ Windows installations (every unpatched install of the listed Windows 10/11/Server builds is affected) |
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
This source does not provide full text. Read it at zerodayinitiative.com.