ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-542?
ZDI-26-542 has a CVSS rating of 7.8, indicating a high severity level.
How do I fix ZDI-26-542?
To fix ZDI-26-542, ensure that you apply the latest security updates provided by Microsoft for affected versions of Windows.
What types of attacks does ZDI-26-542 enable?
ZDI-26-542 enables local privilege escalation attacks, allowing attackers to gain higher-level permissions on the system.
Who is affected by ZDI-26-542?
ZDI-26-542 affects users running vulnerable installations of Microsoft Windows.
What is the nature of the flaw in ZDI-26-542?
The flaw in ZDI-26-542 is related to improper object management within the UMPDDrvBitBlt component.