Link following in Microsoft Windows - CVE-2026-72971
Published: August 12, 2026
Vulnerability identifier: #VU141872
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-72971
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to modify files.
The vulnerability exists due to improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) when accessing files through links. A local user can create a link to a target file to modify files.
Affected software
Microsoft Windows
How to mitigate CVE-2026-72971
Install security update from vendor's website.
Microsoft Windows - update to 11 26H1 10.0.28000.2704