Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62737

CVE-2026-62737: Windows 11 24H2 Privilege Escalation Flaw

CVE-2026-62737 is a privilege escalation vulnerability in Windows 11 24H2 caused by untrusted pointer dereference in the Windows Kernel. This article covers technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-62737 Overview

CVE-2026-62737 is a local privilege escalation vulnerability in the Microsoft Windows Kernel. The flaw stems from an untrusted pointer dereference [CWE-822] that an authenticated attacker can trigger to elevate privileges on affected systems. Successful exploitation grants the attacker high impact to confidentiality, integrity, and availability, effectively yielding SYSTEM-level control from a low-privilege account. The issue affects current Windows 11 servicing branches (24H2, 25H2, 26H1) and Windows Server 2025 across both x64 and ARM64 architectures. Microsoft published the advisory through the Microsoft Security Response Center (MSRC) update guide.

Critical Impact

An authenticated local attacker can escalate to kernel-level privileges, bypassing user account boundaries and gaining full control of the host.

Affected Products

  • Microsoft Windows 11 version 24H2 (x64, ARM64)
  • Microsoft Windows 11 versions 25H2 and 26H1 (x64, ARM64)
  • Microsoft Windows Server 2025

Discovery Timeline

  • 2026-08-11 - CVE-2026-62737 published to the National Vulnerability Database (NVD)
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-62737

Vulnerability Analysis

The vulnerability resides in the Windows Kernel and is categorized as an untrusted pointer dereference [CWE-822]. Kernel code dereferences a pointer whose value originates from, or can be influenced by, a lower-privileged user-mode caller without sufficient validation. When the kernel operates on that pointer, it reads or writes memory at an attacker-controlled address in ring 0. This condition enables arbitrary kernel memory corruption, which attackers convert into privilege escalation by overwriting security tokens or function pointers used during scheduling. The CVSS vector reports a local attack vector with low attack complexity and no user interaction, meaning any process running under an interactive or service account on the target host can attempt exploitation.

Root Cause

The root cause is missing or incorrect validation of a pointer that crosses the user-to-kernel trust boundary. Windows kernel routines must validate that pointers received from user mode reference user-accessible memory before dereferencing them, typically through ProbeForRead or ProbeForWrite. When these checks are omitted or bypassed, the kernel treats attacker-supplied addresses as trusted, permitting reads or writes to arbitrary kernel virtual memory.

Attack Vector

Exploitation requires local access with valid credentials. An attacker executes a crafted program that issues system calls or IOCTLs carrying malicious pointer values into the vulnerable kernel path. Because no user interaction is required and the attack complexity is low, the vulnerability is well-suited to post-compromise chaining. Adversaries commonly pair such kernel flaws with initial-access techniques including phishing payloads, browser exploits, or stolen credentials to complete a full compromise. No public proof-of-concept or in-the-wild exploitation has been reported at the time of publication, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Microsoft has not published exploitation code. See the Microsoft Security Update Guide for CVE-2026-62737 for the authoritative technical description.

Detection Methods for CVE-2026-62737

Indicators of Compromise

  • Unexpected processes spawning child processes running as NT AUTHORITY\SYSTEM from a non-elevated parent.
  • Kernel bug checks (BSOD) referencing SYSTEM_SERVICE_EXCEPTION or KERNEL_MODE_EXCEPTION_NOT_HANDLED correlated with a specific user-mode process.
  • Loading of unsigned or unusual drivers immediately before token modification events.
  • Anomalous handle duplication or token impersonation events (Windows Event ID 4696, 4672) tied to standard user accounts.

Detection Strategies

  • Monitor for token integrity level transitions where a Medium integrity process suddenly holds a System-level token.
  • Correlate Sysmon Event ID 10 (process access with PROCESS_VM_WRITE) against lsass.exe or System with unusual source processes.
  • Baseline expected callers of sensitive NtDeviceIoControlFile paths and flag deviations from low-privilege processes.
  • Alert on driver load events (Sysmon Event ID 6) followed shortly by privilege elevation on the same host.

Monitoring Recommendations

  • Ingest Windows Security, System, and Sysmon logs into a centralized analytics platform for cross-host correlation.
  • Track patch compliance for the August 2026 Windows cumulative updates across all Windows 11 and Server 2025 endpoints.
  • Enable kernel-mode telemetry via Event Tracing for Windows (ETW) providers focused on process token and driver events.

How to Mitigate CVE-2026-62737

Immediate Actions Required

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2026-62737 to every affected Windows 11 and Windows Server 2025 host.
  • Prioritize patching on multi-user systems, jump hosts, and terminal servers where local access is expected.
  • Audit local user and service account privileges and remove unnecessary interactive logon rights.
  • Enable Hypervisor-Protected Code Integrity (HVCI) and Virtualization-Based Security (VBS) to raise the bar for kernel exploitation.

Patch Information

Microsoft has released cumulative updates addressing CVE-2026-62737 for Windows 11 24H2, 25H2, and 26H1, and Windows Server 2025. The specific KB article and build numbers are published in the Microsoft Security Update Guide. Administrators should deploy the update through Windows Update, Windows Server Update Services (WSUS), or Microsoft Intune according to their patch management policy.

Workarounds

  • No official workaround has been published by Microsoft. Patching is the required remediation.
  • Restrict local logon to trusted administrators until the update is deployed.
  • Enforce application allowlisting with Windows Defender Application Control (WDAC) or AppLocker to limit unsigned binary execution.
  • Enable attack surface reduction (ASR) rules that block credential theft and process injection to constrain post-exploitation activity.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.