ZDI-CAN-30747: ZDI-26-542: Microsoft Windows UMPDDrvBitBlt Improper Object Management Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-62712.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-30747?
ZDI-CAN-30747 has a CVSS rating of 7.8, indicating it is a high-severity vulnerability.
How do I fix ZDI-CAN-30747?
To mitigate ZDI-CAN-30747, users should apply the latest security updates provided by Microsoft for their Windows installation.
What kind of systems are affected by ZDI-CAN-30747?
ZDI-CAN-30747 affects installations of Microsoft Windows that utilize the UMPDDrvBitBlt function.
Who can exploit the ZDI-CAN-30747 vulnerability?
Local attackers who have access to execute low-privileged code on the system can exploit the ZDI-CAN-30747 vulnerability.
What is the impact of ZDI-CAN-30747 on my system?
Exploiting ZDI-CAN-30747 allows attackers to escalate their privileges, potentially leading to unauthorized access or control over the system.