Impact
Microsoft PC Manager contains a flaw in which the application performs link resolution before accessing files, a behavior referred to as "link following." An attacker who has legitimate local access to the system can craft a link that points to a file under higher privilege control. When PC Manager follows that link, it accesses the file with elevated rights, enabling the attacker to gain additional local privileges. The weakness is classified as CWE‑59.
Affected Systems
Microsoft PC Manager is the affected product. No specific version information is provided, so any installation of the application is potentially vulnerable until a vendor update is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 8.8, indicating high severity, but the EPSS score of less than 1% signals a very low likelihood of exploitation in the wild at present. It is not listed in the CISA KEV catalog, suggesting no known active exploitation. Because the flaw can be triggered only by a user who is already authorized to use PC Manager, the risk is tied to local or compromised legitimate accounts, including potential insider misuse.
OpenCVE Enrichment