Link following in Microsoft Windows and Windows Server - CVE-2026-83999
Published: September 9, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to improper link resolution before file access (\'link following\') in the Windows Resilient File System (ReFS) Deduplication Service when accessing files. A local user can win a race condition to escalate privileges.
Successful exploitation could grant SYSTEM privileges.
Affected software
Windows Server
How to mitigate CVE-2026-83999
Windows Server - update to 2025 10.0.26100.33438