High severity7.8NVD Advisory· Published Aug 11, 2026· Updated Aug 13, 2026
CVE-2026-62832
CVE-2026-62832
Description
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
Affected products
17cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*+ 5 more
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*range: <10.0.19044.7663
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*range: <10.0.19044.7663
- cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*range: <10.0.19044.7663
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*range: <10.0.19045.7663
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*range: <10.0.19045.7663
- cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*range: <10.0.19045.7663
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*range: <10.0.22631.7517
- cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*range: <10.0.22631.7517
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*range: <10.0.26100.9168
- cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*range: <10.0.26100.9168
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*range: <10.0.26200.9168
- cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*range: <10.0.26200.9168
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*+ 1 more
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*range: <10.0.28000.2704
- cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*range: <10.0.28000.2704
- cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*Range: <10.0.20348.5499
- cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*Range: <10.0.26100.33296
Patches
Vulnerability mechanics
References
1- msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62832nvdVendor Advisory
News mentions
17- Cyber Security Weekly Newsletter – Outlook RCE, Palo Alto, Cisco 0-day and Windows 0-Day Flaws +20 StoriesCyber Security News · Aug 16, 2026
- Patch Tuesday: Update now to fix 421 flaws, including three zero-daysMalwarebytes Labs · Aug 12, 2026
- Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discoveryThe Record · Aug 12, 2026
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)Help Net Security · Aug 12, 2026
- Microsoft Fixes 400 Flaws on August Patch TuesdayInfosecurity Magazine · Aug 12, 2026
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM AccessThe Hacker News · Aug 12, 2026
- Microsoft Patch Tuesday for August 2026 — Snort rules and prominent vulnerabilitiesCisco Talos Intelligence · Aug 11, 2026
- Microsoft's Patch Tuesday Deluge Continues With August UpdatesDark Reading · Aug 11, 2026
- 421 bugs in Microsoft's Patch Tuesday release, and the Norks have already attacked oneThe Register Security · Aug 11, 2026
- Microsoft Plugs Nearly 400 Security HolesKrebs on Security · Aug 11, 2026
- Patch Tuesday - August 2026Rapid7 Blog · Aug 11, 2026
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek · Aug 11, 2026
- Microsoft's August 2026 Patch Tuesday addresses 398 CVEs (CVE-2026-68820)Tenable Blog · Aug 11, 2026
- Microsoft Patch Tuesday August 2026, (Tue, Aug 11th)SANS Internet Storm Center · Aug 11, 2026
- Microsoft Patch Tuesday Update August 2026 – 394 Vulnerabilities Fixed, Including 3 Zero-DaysCyber Security News · Aug 11, 2026
- Windows 11 24H2: 25 Vulnerabilities Patched, Including Exploited Zero-Day CVE-2026-68820Vypr Intelligence · Aug 11, 2026
- August 2026 Patch Tuesday: One Exploited Zero-Day and 62 Critical Vulnerabilities Among 415 CVEsCrowdStrike Blog