Link following in Windows and Windows Server - CVE-2026-45586
Published: June 12, 2026
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows Collaborative Translation Framework (CTFMON). A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.