Link following in Microsoft Windows and Windows Server - CVE-2026-45586
Published: June 12, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows Collaborative Translation Framework (CTFMON). A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Affected software
Windows Server
How to mitigate CVE-2026-45586
Windows Server - addressed in versions 2004 10.0.19045.7417, 2012 R2 6.3.9600.23228, 2012 6.2.9200.26132, 2016 10.0.14393.9234, 2019 10.0.17763.8880, 2022 10.0.20348.5256, 2025 10.0.26100.32995