Windows Win32k Elevation of Privilege Vulnerability

Date Aug 11, 2026
Type Patch Tuesday
Signal High-risk advisory
Vendor / Product Microsoft ยท Windows Win32K
CVE CVE-2026-62712
High-risk advisory CVE-2026-62712

Summary

Heap-based buffer overflow in Windows Win32K allows an authorized attacker to elevate privileges locally. Published in August 2026 Security Updates. MSRC exploitability: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation More Likely.

Why it matters

Microsoft published this item through its Security Update Guide, making it part of Patch Tuesday triage for affected Windows, cloud, or application estates. EPSS percentile: 32%.

Operator check

Review the Microsoft Security Update Guide entry for CVE-2026-62712. Confirm whether Windows Win32K is deployed, then apply the current security update or documented mitigation. CVSS score: 7.8. EPSS probability: 0.4%; percentile: 32%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.