• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-62737: local privilege escalation in Microsoft Windows 11 Version 24H2

A local, authorized user can exploit an untrusted pointer dereference in the Windows kernel to elevate privileges on Windows 11 and Windows Server 2025 systems (CVE-2026-62737). Affected builds include Windows 11 Version 24H2 (10.0.26100.0 through before 10.0.26100.9168), Version 25H2 (10.0.26200.0 through before 10.0.26200.9168), Version 26H1 (10.0.28000.0 through before 10.0.28000.2704), and Windows Server 2025 builds noted; the attacker requires local access with low privileges and no additional user interaction.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7.8HIGH
EPSS
0.00333
CWE
CWE-822
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so prioritize installing the vendor fixes for the listed builds immediately or restrict local account exposure until updates can be applied.

What is CVE-2026-62737?

A local, authorized user can exploit an untrusted pointer dereference in the Windows kernel to elevate privileges on Windows 11 and Windows Server 2025 systems (CVE-2026-62737). Affected builds include Windows 11 Version 24H2 (10.0.26100.0 through before 10.0.26100.9168), Version 25H2 (10.0.26200.0 through before 10.0.26200.9168), Version 26H1 (10.0.28000.0 through before 10.0.28000.2704), and Windows Server 2025 builds noted; the attacker requires local access with low privileges and no additional user interaction.

Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 11 Version 24H2 are affected?

BRANCHAFFECTEDFIXED
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.916810.0.26100.9168
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.916810.0.26200.9168
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.270410.0.28000.2704
Windows Server 2025 10.x10.0.26100.0 – before 10.0.26100.3329610.0.26100.33296
Windows Server 2025 (Server Core installation) 10.x10.0.26100.0 – before 10.0.26100.3329610.0.26100.33296

Is CVE-2026-62737 being exploited?

Public exploit code is available.

How to fix CVE-2026-62737

  1. Install Microsoft updates that move affected builds to the fixed builds (10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and 10.0.26100.33296 as listed).
  2. Restrict and review local account privileges and limit unnecessary local logon access to affected systems.
  3. Monitor endpoint and security logs for signs of privilege escalation and suspicious local activity.
  4. Follow Microsoft guidance and deploy updates in test then production according to your change control process.

Frequently asked questions

Is CVE-2026-62737 being actively exploited?

Public exploit code for CVE-2026-62737 is available.

Which Windows 11 Version 24H2 versions are affected by CVE-2026-62737?

Windows 11 Version 24H2 builds from 10.0.26100.0 up to but not including 10.0.26100.9168 are affected.

Is there a patch for CVE-2026-62737?

Yes. Microsoft published fixes that update affected builds to 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and 10.0.26100.33296 for the listed branches.

Does CVE-2026-62737 require authentication?

Yes. The flaw requires a local, authorized (low-privileged) account on affected Windows 11 or Windows Server 2025 systems to exploit.

References