Description
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. The flaw, classified under CWE-59, indicates insufficient restrictions on file access operations, enabling a local user with basic rights to exploit the link mechanism and gain higher privileges within the system.

Affected Systems

Microsoft PC Manager is impacted. No specific affected versions are listed in the data. The product is listed under the Microsoft CNA. Users should verify whether their installed version includes the fix and apply any available security updates from Microsoft.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity for local attackers. The EPSS score is less than 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exposing the flaw requires a local attacker with authorized access to manipulate the link resolution path; successful exploitation would provide elevated privileges on the host.

Generated by OpenCVE AI on July 31, 2026 at 09:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Microsoft security update for PC Manager from the Microsoft Security Response Center
  • Restrict creation or modification of symbolic links or other link‑like filesystem objects to privileged users only
  • Apply the principle of least privilege to the PC Manager service and limit its access to necessary system resources

Generated by OpenCVE AI on July 31, 2026 at 09:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally.
Title Microsoft PC Manager Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft pc Manager
Weaknesses CWE-59
CPEs cpe:2.3:a:microsoft:pc_manager:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft pc Manager
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Pc Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:23:12.128Z

Reserved: 2026-07-01T21:14:44.617Z

Link: CVE-2026-58636

cve-icon Vulnrichment

Updated: 2026-07-14T17:34:06.909Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')