Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has released security updates for CVE-2026-62698, Microsoft Digest Authentication Elevation of Privilege Vulnerability, an Important-rated flaw affecting a broad range of supported Windows client and server releases.

The issue is a numeric truncation error in Microsoft Digest Authentication. Microsoft states: “Microsoft Digest Authentication Elevation of Privilege Vulnerability: Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.”

An attacker who successfully exploits the vulnerability could gain SYSTEM privileges, according to Microsoft’s advisory. That makes this a meaningful patching priority: SYSTEM is Windows’ highest local privilege level, the keys-to-the-kingdom account rather than merely another seat in the castle.

Vulnerability details​

  • CVE: CVE-2026-62698
  • Title: Microsoft Digest Authentication Elevation of Privilege Vulnerability
  • Severity: Important
  • CVSS base score: 7.8
  • CVSS temporal score: 6.8
  • CVSS vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
  • CWE: CWE-197
  • Description: Numeric truncation error in Microsoft Digest Authentication allows an authorized attacker to elevate privileges locally.

Publicly disclosed: No
Exploited: No
Customer action required: Yes

Microsoft’s exploitation assessment is Exploitation More Likely.

The CVSS vector describes a locally exploitable issue with low attack complexity, where the attacker must already hold low-level privileges. No user interaction is required. A successful attack can affect confidentiality, integrity, and availability at a high level. In practical terms, this is not a remote unauthenticated break-in, but it can turn an existing foothold on a machine into complete local control.

Why this patch matters​

Elevation-of-privilege vulnerabilities are often most dangerous as part of a chain. An attacker may first obtain a limited account or limited code execution through another route, then use a local privilege escalation bug to reach SYSTEM. At that point, ordinary Windows permission boundaries provide very little resistance.

Microsoft’s advisory explicitly addresses the potential outcome:

“What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”

That risk applies to both workstation and server estates, including Server Core installations. Server administrators should not mistake a minimal GUI footprint for immunity; if an affected component is present and unpatched, the operating system version still requires the relevant update.

Affected Windows versions and fixed builds​

The following Microsoft updates remediate CVE-2026-62698. Administrators should deploy the applicable cumulative update for each operating system and architecture in their environment, then confirm the corresponding build number.

Windows 10​

  • Windows 10 Version 1607 for 32-bit Systems (x86): For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5120418 to reach fixed build 10.0.14393.9418.
  • Windows 10 Version 1607 for x64-based Systems: For Windows 10 Version 1607 for x64-based Systems, install KB5120418 to reach fixed build 10.0.14393.9418.
  • Windows 10 Version 1809 for 32-bit Systems (x86): For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5120238 to reach fixed build 10.0.17763.9121.
  • Windows 10 Version 1809 for x64-based Systems: For Windows 10 Version 1809 for x64-based Systems, install KB5120238 to reach fixed build 10.0.17763.9121.
  • Windows 10 Version 21H2 for 32-bit Systems (x86): For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5120249 to reach fixed build 10.0.19044.7663.
  • Windows 10 Version 21H2 for ARM64-based Systems: For Windows 10 Version 21H2 for ARM64-based Systems, install KB5120249 to reach fixed build 10.0.19044.7663.
  • Windows 10 Version 21H2 for x64-based Systems: For Windows 10 Version 21H2 for x64-based Systems, install KB5120249 to reach fixed build 10.0.19044.7663.
  • Windows 10 Version 22H2 for 32-bit Systems (x86): For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5120249 to reach fixed build 10.0.19045.7663.
  • Windows 10 Version 22H2 for ARM64-based Systems: For Windows 10 Version 22H2 for ARM64-based Systems, install KB5120249 to reach fixed build 10.0.19045.7663.
  • Windows 10 Version 22H2 for x64-based Systems: For Windows 10 Version 22H2 for x64-based Systems, install KB5120249 to reach fixed build 10.0.19045.7663.

Windows 11​

  • Windows 11 Version 23H2 for ARM64-based Systems: For Windows 11 Version 23H2 for ARM64-based Systems, install KB5120240 to reach fixed build 10.0.22631.7517.
  • Windows 11 Version 23H2 for x64-based Systems: For Windows 11 Version 23H2 for x64-based Systems, install KB5120240 to reach fixed build 10.0.22631.7517.
  • Windows 11 Version 24H2 for ARM64-based Systems: For Windows 11 Version 24H2 for ARM64-based Systems, install KB5120994 to reach fixed build 10.0.26100.9106; install KB5121003 to reach fixed build 10.0.26100.9168.
  • Windows 11 Version 24H2 for x64-based Systems: For Windows 11 Version 24H2 for x64-based Systems, install KB5120994 to reach fixed build 10.0.26100.9106; install KB5121003 to reach fixed build 10.0.26100.9168.
  • Windows 11 Version 25H2 for ARM64-based Systems: For Windows 11 Version 25H2 for ARM64-based Systems, install KB5120994 to reach fixed build 10.0.26200.9106; install KB5121003 to reach fixed build 10.0.26200.9168.
  • Windows 11 Version 25H2 for x64-based Systems: For Windows 11 Version 25H2 for x64-based Systems, install KB5120994 to reach fixed build 10.0.26200.9106; install KB5121003 to reach fixed build 10.0.26200.9168.
  • Windows 11 Version 26H1 for ARM64-based Systems: For Windows 11 Version 26H1 for ARM64-based Systems, install KB5121000 to reach fixed build 10.0.28000.2704.
  • Windows 11 version 26H1 for x64-based Systems: For Windows 11 version 26H1 for x64-based Systems, install KB5121000 to reach fixed build 10.0.28000.2704.

Windows Server​

  • Windows Server 2012 (Server Core installation) (x64): For Windows Server 2012 (Server Core installation) (x64), install KB5120386 to reach fixed build 6.2.9200.26280.
  • Windows Server 2012 (x64): For Windows Server 2012 (x64), install KB5120386 to reach fixed build 6.2.9200.26280.
  • Windows Server 2012 R2 (Server Core installation) (x64): For Windows Server 2012 R2 (Server Core installation) (x64), install KB5120385 to reach fixed build 6.3.9600.23338.
  • Windows Server 2012 R2 (x64): For Windows Server 2012 R2 (x64), install KB5120385 to reach fixed build 6.3.9600.23338.
  • Windows Server 2016 (Server Core installation) (x64): For Windows Server 2016 (Server Core installation) (x64), install KB5120418 to reach fixed build 10.0.14393.9418.
  • Windows Server 2016 (x64): For Windows Server 2016 (x64), install KB5120418 to reach fixed build 10.0.14393.9418.
  • Windows Server 2019 (Server Core installation) (x64): For Windows Server 2019 (Server Core installation) (x64), install KB5120238 to reach fixed build 10.0.17763.9121.
  • Windows Server 2019 (x64): For Windows Server 2019 (x64), install KB5120238 to reach fixed build 10.0.17763.9121.
  • Windows Server 2022 (Server Core installation) (x64): For Windows Server 2022 (Server Core installation) (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.
  • Windows Server 2022 (x64): For Windows Server 2022 (x64), install KB5120229 to reach fixed build 10.0.20348.5440; install KB5120242 to reach fixed build 10.0.20348.5499.
  • Windows Server 2025 (Server Core installation) (x64): For Windows Server 2025 (Server Core installation) (x64), install KB5120228 to reach fixed build 10.0.26100.33222; install KB5120233 to reach fixed build 10.0.26100.33296.
  • Windows Server 2025 (x64): For Windows Server 2025 (x64), install KB5120228 to reach fixed build 10.0.26100.33222; install KB5120233 to reach fixed build 10.0.26100.33296.

Administrator checklist​

  1. Inventory Windows versions and architectures. Separate x86, x64, and ARM64 endpoints; the target build is architecture- and release-specific.
  2. Deploy the applicable cumulative update. Use the KB listed for the installed Windows release.
  3. Restart where required. Cumulative Windows security updates commonly require a restart before the revised system components are active.
  4. Validate the installed build. Check winver on client systems or use enterprise inventory tooling to compare the device’s build against the fixed build listed above.
  5. Include server and Server Core systems. Windows Server 2012 through Windows Server 2025 are covered by this advisory, including the specified Server Core installations.
  6. Prioritize systems where local access is realistic. Since the attack is local and requires authorization, systems shared by multiple users or exposed to post-compromise activity warrant particular attention.

The central lesson from CVE-2026-62698 is refreshingly unglamorous but important: a local account should not be able to become SYSTEM through a flaw in authentication handling. Apply the relevant Windows security update, verify the resulting build, and close off an escalation route before it becomes the second act in someone else’s intrusion story.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com