Link following in Microsoft Windows - CVE-2026-72971

 

Link following in Microsoft Windows - CVE-2026-72971

Published: August 12, 2026


Vulnerability identifier: #VU141872
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72971
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to modify files.

The vulnerability exists due to improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) when accessing files through links. A local user can create a link to a target file to modify files.


Affected software

Microsoft Windows

How to mitigate CVE-2026-72971

Install security update from vendor's website.

Microsoft Windows - update to 11 26H1 10.0.28000.2704

External References

Related Security Bulletins