CVE-2026-62832 is a local elevation-of-privilege vulnerability in the Windows User Profile Service caused by improper link resolution before file access. The flaw is a link-following issue in which the service can be induced to resolve and access attacker-influenced links before securely validating the target object. Available reporting indicates that exploitation can allow an authenticated attacker with credentials for another local account to cause the service to load another user’s registry hive, enabling access to or modification of that user’s data. Microsoft and third-party reporting also indicate exploitation is achievable via a specially crafted application and can result in administrator rights on the affected local system. The vulnerability has been publicly disclosed and has been associated in public discussion with the LegacyHive technique.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A publicly known Microsoft vulnerability that Microsoft believes attackers will likely exploit soon; it is highlighted as especially dangerous when chained with CVE-2026-68820 to achieve full system compromise.
A privilege escalation flaw in the Windows User Profile Service that was publicly disclosed and assessed by Microsoft as likely to be exploited.
A Windows elevation-of-privilege vulnerability that allows an authenticated attacker with credentials for another local account to load another user's registry hive, potentially access or modify that user's data, and gain administrator privileges.
A privilege escalation vulnerability in the Windows User Profile Service that Microsoft assesses as likely to be exploited and that may be related to the public LegacyHive disclosure.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.