ThreatCluster

Critical Vulnerabilities in Windows Services Disclosed

First seen 8 Sep 2026, 22:13 UTC Api.Msrc.Microsoftwww.cve.org 69

Article Content

Browse articles
ThreatCluster

Two critical vulnerabilities, CVE-2026-62747 and CVE-2026-57085, were disclosed affecting Windows services. CVE-2026-62747 involves a heap-based buffer overflow in the Windows Device Association Service, allowing attackers to elevate privileges to SYSTEM level. CVE-2026-57085 is an out-of-bounds read in Windows Print Spooler Components, enabling attackers to disclose limited information from system memory. Both vulnerabilities were released on September 8, 2026, with CVE-2026-62747 having an exploitability assessment indicating high risk. The vulnerabilities affect Windows systems, and while CVE-2026-62747 poses a significant threat, CVE-2026-57085 is less severe due to the limited scope of information disclosure. Patches and mitigations are expected to be released shortly. Security professionals are urged to monitor these vulnerabilities closely and apply updates as they become available.

Key Points: • CVE-2026-62747 allows local privilege escalation to SYSTEM level. • CVE-2026-57085 enables limited information disclosure from affected systems. • Both vulnerabilities were disclosed on September 8, 2026, and patches are anticipated.

Ask AI about this cluster

Timeline

2026-07-14
CVE-2026-57085 released
Out-of-bounds read vulnerability disclosed in Windows Print Spooler Components.
Api.Msrc.Microsoft
2026-08-11
CVE-2026-62747 released
Heap-based buffer overflow vulnerability disclosed in Windows Device Association Service.
Api.Msrc.Microsoft
2026-09-08
Vulnerabilities updated
Both vulnerabilities received updates on the same day, indicating their current status.
Api.Msrc.Microsoft