Description
A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
Published: 2026-09-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege escalation to SYSTEM
Action: Patch Now
AI Analysis

Impact

A local privilege escalation vulnerability exists in the Logitech Logi Options+ updater service on Windows. A low‑privileged local user can execute arbitrary code with SYSTEM rights, exploiting an access control flaw identified as CWE‑269. With SYSTEM privileges the attacker can install malware, modify system binaries and take full control of the host.

Affected Systems

All installations of Logitech Logi Options+ that contain the legacy updater service are affected. Versions prior to 2.7 are vulnerable; upgrading to 2.7 or later mitigates the issue. No specific sub‑version ranges are listed beyond the 2.7 threshold.

Risk and Exploitability

The vulnerability carries a CVSS v3.1 score of 8.5, indicating a high‑severity impact. The EPSS score is reported as < 1%, showing a low probability of exploitation, and the vulnerability is not enlisted in CISA KEV. The exploit requires no network access; a local attacker with the ability to run applications or scripts can trigger the flaw, making it straightforward to abuse in multi‑user environments.

Generated by OpenCVE AI on September 15, 2026 at 14:49 UTC.

Remediation

Vendor Solution

Update to Logi Options+ 2.7 or later.


OpenCVE Recommended Actions

  • Upgrade to Logi Options+ 2.7 or later.
  • Disable or remove the Logi Options+ updater service if the device is not required.
  • Restrict file permissions on the updater service executable to prevent execution by standard users.

Generated by OpenCVE AI on September 15, 2026 at 14:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Logitech
Logitech logi Options+
Vendors & Products Logitech
Logitech logi Options+

Mon, 14 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.
Title Local privilege escalation in the Logi Options+ updater service on Windows
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Logitech Logi Options+
cve-icon MITRE

Status: PUBLISHED

Assigner: Logitech

Published:

Updated: 2026-09-14T10:46:16.198Z

Reserved: 2026-06-17T12:51:42.609Z

Link: CVE-2026-12518

cve-icon Vulnrichment

Updated: 2026-09-14T10:46:11.242Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T08:16:34.320

Modified: 2026-09-18T19:31:11.370

Link: CVE-2026-12518

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:00:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management