
A vulnerability in Logitech Options+ allows a standard Windows user to gain SYSTEM-level privileges by exploiting a weakness in the software's updater service.
Tracked as CVE-2026-12518, the issue requires no administrator rights, network access, or additional user interaction. Logitech released a patch on August 19, before AmberWolf Research publicly disclosed the vulnerability on September 14.
Security researcher Jake Bolam of AmberWolf Research discovered the flaw in February while analyzing Logitech Options+ build 667932 on Windows 11. His investigation found that several weaknesses in the way the software trusted local processes and handled installation files could be chained together for privilege escalation.
Logitech Options+ is used to configure and manage supported Logitech mice, keyboards, and other peripherals. On Windows, parts of the application run with normal user privileges, while its updater service operates as NT AUTHORITY\SYSTEM, giving it extensive access to the operating system.
The updater accepted requests only from Logitech's background agent, which initially appeared to prevent other applications from communicating with the privileged service.
However, the agent itself runs with the permissions of the logged-in user. Bolam found that a standard user could manipulate their own instance of that trusted process and use it to relay commands to the updater, bypassing the intended restriction.
Further analysis revealed that the updater also accepted user-controlled values that could influence where installation files were loaded from. This meant an attacker could redirect the service away from Logitech-controlled directories and toward a location where they could place their own files.

AmberWolf
That became more serious because one of the updater's privileged installation routines skipped the certificate validation normally used to verify executables and installers.
By combining these weaknesses, an attacker could place a malicious Windows installer in a writable directory, redirect the updater to it, and have the trusted Logitech service launch it with SYSTEM privileges.
Successful exploitation would give the attacker the highest local privilege level on Windows, potentially allowing them to modify protected files, install software, access other users' data, or interfere with security tools.
AmberWolf reported the vulnerability to Logitech on March 11, and the company acknowledged the report on March 25. The planned remediation date was moved several times before Logitech ultimately released the fix on August 19. The issue was publicly disclosed on September 14 after remediation was available.
Windows users running Logitech Options+ should update to the latest version available, currently 2.7.954611 & 2.7.961922.







Leave a Reply