Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-62832

CVE-2026-62832: Windows 10 21h2 Privilege Escalation Flaw

CVE-2026-62832 is a privilege escalation vulnerability in Windows 10 21h2 User Profile Service caused by improper link resolution. Attackers can exploit this to gain elevated privileges locally.

Published:

CVE-2026-62832 Overview

CVE-2026-62832 is a local privilege escalation vulnerability in the Windows User Profile Service. The flaw stems from improper link resolution before file access, classified as [CWE-59]. An authenticated local attacker can abuse symbolic link or junction handling to redirect privileged file operations and gain elevated privileges on affected systems. Microsoft published the advisory on August 11, 2026, covering multiple Windows client and server releases. The vulnerability carries a CVSS 3.1 score of 7.8 with an EPSS probability of 2.392% (82.48 percentile), indicating meaningful exploitation likelihood relative to the broader CVE population.

Critical Impact

A low-privileged local user can elevate to SYSTEM by manipulating filesystem links processed by the User Profile Service, resulting in full compromise of confidentiality, integrity, and availability.

Affected Products

  • Microsoft Windows 10 (21H2, 22H2) on x86, x64, and ARM64
  • Microsoft Windows 11 (23H2, 24H2, 25H2, 26H1) on x64 and ARM64
  • Microsoft Windows Server 2022 and Windows Server 2025

Discovery Timeline

  • 2026-08-11 - Microsoft publishes advisory for CVE-2026-62832
  • 2026-08-11 - CVE-2026-62832 published to NVD
  • 2026-08-13 - Last updated in NVD database

Technical Details for CVE-2026-62832

Vulnerability Analysis

The Windows User Profile Service (ProfSvc) manages user profile loading, unloading, and directory operations under the LocalSystem account. The service performs file operations on paths that reside under user-writable directories, such as %LOCALAPPDATA% or profile subfolders. When these operations do not properly resolve or reject filesystem reparse points, an attacker can substitute a legitimate path with a symbolic link, mount point, or object manager symlink.

By pre-planting such a link, a low-privileged user forces the SYSTEM-context service to open, create, or modify files at attacker-chosen locations. This enables arbitrary file write or DACL manipulation outside the profile scope, which is a known primitive for escalation to SYSTEM.

Root Cause

The root cause is a link-following weakness [CWE-59]. The User Profile Service accesses files without validating that the target path has not been redirected through a reparse point controlled by the calling user. The check-to-use gap allows the attacker to swap the path between validation and access, a pattern also related to time-of-check to time-of-use handling in filesystem code.

Attack Vector

Exploitation requires local access and low-privilege authenticated execution. The attacker prepares a reparse point in a directory writable by their user account and then triggers a User Profile Service action (for example, sign-in, profile unload, or a service-invoked file operation) that touches the manipulated path. No user interaction is required beyond the attacker's own session. Public proof-of-concept code was not available at publication.

Refer to the Microsoft Security Update CVE-2026-62832 advisory for authoritative technical detail.

Detection Methods for CVE-2026-62832

Indicators of Compromise

  • Creation of NTFS junctions, symbolic links, or object manager symlinks under user profile directories such as %LOCALAPPDATA%\Microsoft, AppData\Local\Temp, or roaming profile paths
  • Unexpected file writes by svchost.exe hosting ProfSvc into system directories like C:\Windows\System32 or C:\ProgramData
  • New or altered scheduled tasks, services, or DLLs owned by SYSTEM immediately after an interactive logon or profile load event

Detection Strategies

  • Enable Windows Sysmon Event IDs 11 (FileCreate) and 15 (FileCreateStreamHash) and alert on file writes performed by svchost.exe -k netsvcs -p -s ProfSvc outside expected profile paths
  • Correlate Security Event ID 4624 (logon) with subsequent SYSTEM-context file creations in user-writable directories
  • Hunt for CreateSymbolicLink, mklink /J, or SetReparsePoint activity by non-administrative processes preceding profile service events

Monitoring Recommendations

  • Ingest endpoint filesystem and process telemetry into a centralized data lake and pivot on ProfSvc behavior anomalies
  • Baseline normal profile load and unload sequences per host to surface deviations that indicate symlink abuse
  • Track post-logon privilege changes on servers and multi-user workstations, where this class of bug has the highest operational impact

How to Mitigate CVE-2026-62832

Immediate Actions Required

  • Apply the Microsoft security update referenced in the MSRC advisory for CVE-2026-62832 to all affected Windows 10, Windows 11, and Windows Server systems
  • Prioritize multi-user hosts, Remote Desktop Session Hosts, and jump servers, where local privilege escalation has the greatest lateral-movement value
  • Audit local accounts and remove unnecessary interactive logon rights on servers to reduce the pool of potential attackers

Patch Information

Microsoft has released fixed builds through the standard Windows Update and WSUS channels. Consult the Microsoft Security Update CVE-2026-62832 advisory for the specific KB article and build numbers that correspond to each affected release, including Windows 10 21H2/22H2, Windows 11 23H2/24H2/25H2/26H1, Windows Server 2022, and Windows Server 2025.

Workarounds

  • No official workaround eliminates the vulnerability; patching is required for full remediation
  • Restrict the ability of standard users to create symbolic links by reviewing the SeCreateSymbolicLinkPrivilege assignment via Group Policy
  • Monitor for reparse point creation in user profile paths and block or alert using endpoint controls until patches are deployed

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.