Link following in Microsoft Malware Protection Engine - CVE-2026-41091
Published: May 21, 2026
Microsoft Malware Protection Engine
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.