Description
Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: 2.8% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A local privileged escalation flaw exists in the Windows Kernel where an authorized attacker can dereference an untrusted pointer. This untrusted pointer dereference (CWE-822) enables the attacker to gain elevated privileges on the system, compromising confidentiality, integrity, and availability by allowing the execution of arbitrary code with kernel privileges.

Affected Systems

Affected systems include Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 and the Server Core installation. The ARM64 architecture is impacted in Windows 11 24H2 and 25H2, while the x64 architecture is affected in Windows 11 26H1.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, and the EPSS score of 3% reflects a moderately low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack vector is local and requires an attacker to already have some level of system access; no additional prerequisites are described. Given the high severity and local nature, the risk remains significant for environments where such privileged attackers could be present.

Generated by OpenCVE AI on August 24, 2026 at 16:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Windows security updates that contain the fix for CVE-2026-62737
  • apply all pending updates on the affected Windows 11 and Windows Server 2025 installations
  • reboot the system to ensure kernel patching takes effect

Generated by OpenCVE AI on August 24, 2026 at 16:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 12 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.
Title Windows Kernel Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-822
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:05:02.384Z

Reserved: 2026-07-14T20:58:12.787Z

Link: CVE-2026-62737

cve-icon Vulnrichment

Updated: 2026-08-12T13:42:43.443Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:25.347

Modified: 2026-08-13T16:56:17.077

Link: CVE-2026-62737

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T17:00:04Z

Weaknesses
  • CWE-822

    Untrusted Pointer Dereference