CVE-2026-62737PoC(microsoft / windows_11_24h2)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_11_24h2 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Untrusted pointer dereference in Windows Kernel allows an authorized attacker to elevate privileges locally.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-822

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_11_24h2
  • windows_11_25h2
  • windows_11_26h1
  • windows_server_2025

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • General: 3 classified signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 7 mentions (2026-08-10); latest day: 1
  • 12 total mentions across 3 days

Affected systems

Vendors
Products
windows_11_24h2windows_11_25h2windows_11_26h1windows_server_2025

Deep dive

Activity timeline12 mentions / 3d
02457Mentions · 2026-08-10: 7Mentions · 2026-08-11: 4Mentions · 2026-08-14: 1PoC Mentioned / Linked · 2026-08-10: 4PoC Mentioned / Linked · 2026-08-11: 1PoC Mentioned / Linked · 2026-08-14: 1Exploit Tool / Code · 2026-08-10: 1Patch / Workaround · 2026-08-10: 1Patch / Workaround · 2026-08-11: 1Patch / Workaround · 2026-08-14: 1Technical Details · 2026-08-10: 3Technical Details · 2026-08-11: 2Technical Details · 2026-08-14: 108-1008-1108-14
Signal classification6 categories
PoC
433.3%
General
325.0%
Disclosure
216.7%
Exploit
18.3%
False Positive
18.3%
Patch
18.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-08-107
Exploit1False Positive1General2PoC3
2026-08-114
Disclosure2General1PoC1
2026-08-141
Patch1
Full discourse12 posts
  • Hai Tung@tacbliw
    PoC

    Someone dropped this Windows LPE writeup online yesterday along with a PoC. But the mentioned CVE-2026-62737 is not released yet, maybe it will be in the Patch Tuesday tomorrow. And the PoC still work in the lastest version of Windows 😂 https://xz.aliyun.com/news/92658

    Post summary

    A Windows local privilege escalation PoC for CVE-2026-62737 has been published and remains functional against the latest Windows build, though the CVE is not yet publicly released.

    6102251230465.8K
    938 followersView on X
  • Nicolas Krassas@Dinosn
    PoC

    Analysis and Exploitation of Windows 11 0 day Kernel Privilege Escalation Vulnerability (CVE-2026-62737) https://xz.aliyun.com/news/92658

    Post summary

    An analysis article announces a zero‑day kernel privilege escalation vulnerability in Windows 11 and indicates the availability of a PoC, but does not report active exploitation or a patch.

    07050245.3K
    161.3K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    🔴 İddiaya göre Çinli bir siber güvenlik platformunda yeni ve henüz Microsoft tarafından duyurulmamış bir Windows Local Privilege Escalation (LPE) açığı yayınlandı. CVE-2026-62737 numarası atandığı söylenen açık için patch'in yarınki Patch Tuesday'de çıkabileceği konuşuluyor. Makaleye göre PoC en güncel Windows sürümlerinde bile çalışıyor. Windows 11'in (özellikle 25H2) bir kernel sürücüsündeki (ExecutionContext.sys) tasarım hatasından kaynaklanan bir yerel yetki yükseltme (LPE) açığı olduğu söylenmekte. Makalede poc[.]zip ve dump dosyası eklenmiş. Makale: https://xz.aliyun.com/news/92658

    Post summary

    A new Windows LPE (CVE‑2026‑62737) has a functional PoC zip, is expected to be patched on Patch Tuesday, with no evidence yet of active exploitation.

    24030243.6K
    2.3K followersView on X
  • Ivan (ethical vulnerability researcher)@Ivanklydz
    General

    https://klydz.net/post.php?slug=analysis-of-a-new-windows-unpatched-0day-cve-2026-62737

    Post summary

    The provided link indicates an analysis of a Windows CVE-2026-62737, but contains no explicit details or claims about PoC, exploit code, active exploitation, patches, or technical specifics.

    25117142.8K
    1.7K followersView on X
  • d3d aka dead (dead, мёртв, 死了)@deadvolvo
    General

    CVE-2026-62737 - Interesting... https://xz.aliyun.com/news/92658 https://t.co/HmypxKy2fN

    Post summary

    The tweet merely notes that CVE-2026-62737 is interesting and links to an article, but offers no additional technical details, PoC, exploitation, or mitigation information.

    0201381.8K
    5.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    PoC

    👉 CVE-2026-62737 ile ilgili yayınlanan bağımsız bir analizde, paylaşılan PoC'nin şu an için BSOD/crash oluşturduğu, ancak SYSTEM yetkisi elde ettiğinin gösterilmediği de iddia ediliyor. Ancak açığın olduğunu varsayıp, temkinli olup, yama geldiğinde mutlaka güncelleyin.

    Post summary

    An independent analysis reports a PoC for CVE-2026-62737 that triggers a BSOD but does not elevate to SYSTEM privileges; users are advised to update once a patch is released.

    00020251
    2.3K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Microsoft #PatchTuesday fixes the #CVE-2026-62737, a vulnerability in the #Windows #Kernel that could allow a local attacker to escalate privileges to #SYSTEM, potentially leading to full compromise. #PoC Read the updated advisory: https://ccb.belgium.be/advisories/warning-microsoft-patch-tuesday-august-2026-patches-398-vulnerabilities-42-critical-355 #Patch

    Post summary

    The advisory announces that Microsoft PatchTuesday includes a fix for CVE-2026-62737, a local privilege escalation flaw in the Windows kernel, and notes a PoC exists but no active exploitation or vulnerability details beyond the privilege escalation are reported.

    01000339
    7.2K followersView on X
  • The CyberSec Guru@thecybersecguru
    Disclosure

    CVE-2026-62737: a Windows 11 kernel LPE built around trust, not memory corruption. Full analysis: https://thecybersecguru.com/news/cve-2026-62737-windows-11-kernel-zero-day/ ndis.sys exposes a KLoader proxy → ExecutionContext.sys accepts the request → QueueTask() stores two attacker-controlled QWORDs → the worker eventually executes the callback. The key mistake? Treating MmSystemRangeStart as a sufficient callback validation check

    Post summary

    The post discloses CVE-2026-62737 as a Windows 11 kernel local privilege escalation stemming from improper callback validation, offering technical details but no PoC, exploit, or patch information.

    00010143
    1.2K followersView on X
  • d45id@d45id
    Exploit

    Windows11 0day内核提权漏洞分析与利用(CVE-2026-62737) 作者:用户lb3tyjtIxQ https://xz.aliyun.com/spa/news/92658

    Post summary

    This post announces a Windows 11 zero‑day kernel privilege‑escalation vulnerability (CVE‑2026‑62737) and indicates that analysis and exploitation details are available via the linked article.

    0000192
    68 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-62737 CVE-2026-62737 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-62737

    Post summary

    The content merely lists CVE-2026-62737 and links to a vulnerability details page, offering no additional context or details about the vulnerability.

    00000126
    4.1K followersView on X
  • T1erOne@tieroneforum
    Disclosure

    Анализ: ExecutionContext.sys в Windows 11 — LPE через RIP-хайджек в NDIS KLoader (CVE-2026-62737) https://tier1.life/thread/485 http://tieronemkfevyizxcnt355agysp2iemvhon6iyclwrc7yuc7oszgzrid.onion/thread/485 #articles #0day #Windows11 #CVE

    Post summary

    The post presents an analysis of a Windows 11 LPE vulnerability (CVE‑2026‑62737) involving a RIP hijack in NDIS KLoader, but does not offer a PoC, exploit code, active exploitation report, or patch information.

    00000252
    300 followersView on X
  • Windows Forum@windowsforum
    False Positive

    ⚠️ CVE-2026-62737 is still an anonymous claim, not a confirmed Windows 11 zero-day. A crash PoC before Patch Tuesday is cybersecurity’s favorite way to ruin everyone’s lunch. https://windowsforum.com/windows-news.4/cve-2026-62737-no-windows-11-flaw-or-fix-confirmed.442266/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #Windows11 #KernelSecurity #PatchTuesday #Cve202662737 https://t.co/NmcvTR4FN7

    Post summary

    The tweet asserts that CVE‑2026‑62737 is an unverified, likely false claim with no confirmed vulnerability, PoC, or exploitation evidence.

    00000145
    1.3K followersView on X
CPE platform detail7 entries

7 of 7 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_11_25h2--arm64
OSmicrosoftwindows_11_25h2--x64
OSmicrosoftwindows_11_26h1--arm64
OSmicrosoftwindows_11_26h1--x64
OSmicrosoftwindows_server_2025---

Explore more