Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4996 articles · 189019 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-62832PATCHED
Microsoft · Windows 10 Version 21H2

Windows User Profile Service Elevation of Privilege Vulnerability

Description

Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
MicrosoftWindows 10 Version 21H210.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
googlegoogle cloudcert_advisory90%
lenovolenovo computercert_advisory90%
microsoftwindows 11 version 25h2mitre_affected90%
microsoftwindows 10 version 22h2mitre_affected90%
microsoftwindowsmitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832(vendor-advisory, patch)

Related News (8 articles)

Tier D
Infosecurity Magazine12h ago
Microsoft Fixes 400 Flaws on August Patch Tuesday
→ No new info (linked only)
Tier B
BSI Advisories12h ago
[NEU] [kritisch] Microsoft Windows Produkte: Mehrere Schwachstellen
→ No new info (linked only)
Tier D
Heise Security12h ago
Patchday: Angreifer attackieren Windows und verschaffen sich System-Rechte
→ No new info (linked only)
Tier B
CERT-FR20h ago
Multiples vulnérabilités dans Microsoft Windows (12 août 2026)
→ No new info (linked only)
Tier C
VulDB23h ago
CVE-2026-62832 | Microsoft Windows up to Server 2025 User Profile Service improper authorization
→ No new info (linked only)
Tier D
SecurityWeek1d ago
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day
→ No new info (linked only)
Tier A
Microsoft MSRC1d ago
CVE-2026-62832 Windows User Profile Service Elevation of Privilege Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog1d ago
August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEs
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV❌ No
Actively exploited❌ No
Patch available
10.0.19044.766310.0.19045.766310.0.22631.751710.0.26100.916810.0.26200.916810.0.28000.270410.0.20348.549910.0.26100.33296
CWECWE-59
PublishedAug 11, 2026
Last enriched1d ago
Trending Score62
Source articles8
Independent8
Info Completeness7/14
Missing: title, description, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 154
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 153
HIGHCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 152
HIGHCVE-2026-50656EXP
Microsoft Defender Elevation of Privilege Vulnerability
Trending: 97
CRITICALCVE-2026-50522EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 76

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Patch Available
Aug 12, 2026