Link following in Windows and Windows Server - CVE-2022-22002
Published: February 8, 2022 / Updated: February 12, 2022
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insecure link following within the UserTileBroker component when processing profile picture. A local user can create a symbolic link to a critical file on the system and perform a denial of service (DoS) attack.