Description
Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft PC Manager contains a flaw in which the application performs link resolution before accessing files, a behavior referred to as "link following." An attacker who has legitimate local access to the system can craft a link that points to a file under higher privilege control. When PC Manager follows that link, it accesses the file with elevated rights, enabling the attacker to gain additional local privileges. The weakness is classified as CWE‑59.

Affected Systems

Microsoft PC Manager is the affected product. No specific version information is provided, so any installation of the application is potentially vulnerable until a vendor update is applied.

Risk and Exploitability

The vulnerability has a CVSS score of 8.8, indicating high severity, but the EPSS score of less than 1% signals a very low likelihood of exploitation in the wild at present. It is not listed in the CISA KEV catalog, suggesting no known active exploitation. Because the flaw can be triggered only by a user who is already authorized to use PC Manager, the risk is tied to local or compromised legitimate accounts, including potential insider misuse.

Generated by OpenCVE AI on July 31, 2026 at 07:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Microsoft PC Manager security update that addresses the link resolution flaw
  • Configure filesystem permissions so that only the accounts required for normal operation can write to the PC Manager installation and configuration directories
  • Set up log monitoring for unusual file access or privilege change events within the PC Manager environment

Generated by OpenCVE AI on July 31, 2026 at 07:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.
Title Microsoft PC Manager Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft pc Manager
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:pc_manager:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft pc Manager
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Pc Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:54.415Z

Reserved: 2026-06-04T18:57:47.376Z

Link: CVE-2026-50438

cve-icon Vulnrichment

Updated: 2026-07-15T10:29:30.927Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:00:04Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')