Impact
Improper link resolution before file access in the Windows Server Backup feature allows a locally authenticated user to elevate privileges by crafting a link file that points to a protected location. When the backup service processes the link, it follows the reference with higher privileges, effectively granting the attacker administrative rights. This flaw is categorized as CWE-59 and results in a local privilege escalation that can lead to full system compromise if the attacker obtains the ability to run arbitrary code or modify system configuration.
Affected Systems
The vulnerability affects Microsoft Windows operating systems including Windows 10 version 21H2, Windows 10 version 22H2, Windows 11 version 24H2, Windows 11 version 25H2, and Windows 11 version 26H1. It is present in the Windows Server Backup service and impacts systems running on x86, x64, and arm64 architectures. Users of these OS versions should review their installed updates and ensure the relevant patch is installed.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity for this local privilege escalation, while the EPSS score of <1% suggests a low likelihood of widespread exploitation at this time. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog, meaning there is no evidence of active exploitation in the wild. Attackers need local access and the ability to interact with the backup service; however, any user with sufficient privileges to create or modify link files can potentially trigger the flaw to raise their own privileges.
OpenCVE Enrichment