CVE-2026-12518 PUBLISHED

Local privilege escalation in the Logi Options+ updater service on Windows

Assigner: Logitech
Reserved: 17.06.2026 Published: 14.09.2026 Updated: 14.09.2026

A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privileged local user to execute arbitrary code as SYSTEM.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.5

Product Status

Vendor Logitech
Product Logi Options+
Versions Default: unaffected
  • affected from 1.88.0 to 2.7.0 (excl.)

Solutions

Update to Logi Options+ 2.7 or later.

Credits

  • Jake Bolam @ AmberWolf finder

References

Problem Types

  • CWE-269 Improper Privilege Management CWE

Impacts

  • CAPEC-233 Privilege Escalation
  • CAPEC-69 Target Programs with Elevated Privileges