Impact
Improper link resolution before file access ('link following') in Window PC Manager allows an authorized attacker to elevate privileges locally. The flaw, classified under CWE-59, indicates insufficient restrictions on file access operations, enabling a local user with basic rights to exploit the link mechanism and gain higher privileges within the system.
Affected Systems
Microsoft PC Manager is impacted. No specific affected versions are listed in the data. The product is listed under the Microsoft CNA. Users should verify whether their installed version includes the fix and apply any available security updates from Microsoft.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity for local attackers. The EPSS score is less than 1%, indicating a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exposing the flaw requires a local attacker with authorized access to manipulate the link resolution path; successful exploitation would provide elevated privileges on the host.
OpenCVE Enrichment