DIRAS TAKE
Urgent: public exploit code exists, so prioritize installing the vendor fixes for the listed builds immediately or restrict local account exposure until updates can be applied.
What is CVE-2026-62737?
A local, authorized user can exploit an untrusted pointer dereference in the Windows kernel to elevate privileges on Windows 11 and Windows Server 2025 systems (CVE-2026-62737). Affected builds include Windows 11 Version 24H2 (10.0.26100.0 through before 10.0.26100.9168), Version 25H2 (10.0.26200.0 through before 10.0.26200.9168), Version 26H1 (10.0.28000.0 through before 10.0.28000.2704), and Windows Server 2025 builds noted; the attacker requires local access with low privileges and no additional user interaction.
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of Microsoft Windows 11 Version 24H2 are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Windows 11 Version 24H2 10.x | 10.0.26100.0 – before 10.0.26100.9168 | 10.0.26100.9168 |
| Windows 11 Version 25H2 10.x | 10.0.26200.0 – before 10.0.26200.9168 | 10.0.26200.9168 |
| Windows 11 version 26H1 10.x | 10.0.28000.0 – before 10.0.28000.2704 | 10.0.28000.2704 |
| Windows Server 2025 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
| Windows Server 2025 (Server Core installation) 10.x | 10.0.26100.0 – before 10.0.26100.33296 | 10.0.26100.33296 |
Is CVE-2026-62737 being exploited?
Public exploit code is available.
How to fix CVE-2026-62737
- Install Microsoft updates that move affected builds to the fixed builds (10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and 10.0.26100.33296 as listed).
- Restrict and review local account privileges and limit unnecessary local logon access to affected systems.
- Monitor endpoint and security logs for signs of privilege escalation and suspicious local activity.
- Follow Microsoft guidance and deploy updates in test then production according to your change control process.
Frequently asked questions
Is CVE-2026-62737 being actively exploited?
Public exploit code for CVE-2026-62737 is available.
Which Windows 11 Version 24H2 versions are affected by CVE-2026-62737?
Windows 11 Version 24H2 builds from 10.0.26100.0 up to but not including 10.0.26100.9168 are affected.
Is there a patch for CVE-2026-62737?
Yes. Microsoft published fixes that update affected builds to 10.0.26100.9168, 10.0.26200.9168, 10.0.28000.2704, and 10.0.26100.33296 for the listed branches.
Does CVE-2026-62737 require authentication?
Yes. The flaw requires a local, authorized (low-privileged) account on affected Windows 11 or Windows Server 2025 systems to exploit.
References
- nvd.nist.gov/vuln/detail/CVE-2026-62737
- cve.org/CVERecord?id=CVE-2026-62737
- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62737
- All Microsoft CVEs on CVE Radar
- CVEs published in September 2026