CVE-2026-62832: stato di sfruttamento e disponibilità della patch
CVE-2026-62832 · CVSS 7.8 HIGH · patch disponibile
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
CVE-2026-62832 viene sfruttato?
Non è nel catalogo CISA KEV.
Codice di exploit pubblico: nessuno trovato nelle fonti monitorate.
Quali prodotti e versioni sono interessati?
Microsoft · Windows Server 2022 · < 10.0.20348.5499, < 10.0.20348.5440
Microsoft · Windows Server 2022 (Server Core installation) · < 10.0.20348.5499, < 10.0.20348.5440
Microsoft · Windows 10 Version 21H2 for 32-bit Systems · < 10.0.19044.7663
Microsoft · Windows 10 Version 21H2 for ARM64-based Systems · < 10.0.19044.7663
Microsoft · Windows 10 Version 21H2 for x64-based Systems · < 10.0.19044.7663
Microsoft · Windows Server 2025 · < 10.0.26100.33296, < 10.0.26100.33222
Microsoft · Windows Server 2025 (Server Core installation) · < 10.0.26100.33296, < 10.0.26100.33222
Microsoft · Windows 11 Version 25H2 for ARM64-based Systems · < 10.0.26200.9168, < 10.0.26200.9106
Microsoft · Windows 11 Version 25H2 for x64-based Systems · < 10.0.26200.9168, < 10.0.26200.9106
Microsoft · Windows 11 Version 23H2 for ARM64-based Systems · < 10.0.22631.7517
Microsoft · Windows 11 Version 23H2 for x64-based Systems · < 10.0.22631.7517
Microsoft · Windows 11 Version 26H1 for ARM64-based Systems · < 10.0.28000.2704
Microsoft · Windows 11 version 26H1 for x64-based Systems · < 10.0.28000.2704