#VU118316 Link following in Windows - CVE-2025-60710
Published: November 11, 2025 / Updated: April 13, 2026
Windows
Microsoft
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Host Process for Windows Tasks. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.