Impact
The flaw is an improper link resolution before file access, or link following, in Windows Accessibility Infrastructure (ATBroker.exe). The trusted component can dereference user‑controlled paths without sufficient validation, a weakness identified as CWE‑59. When an authorized attacker supplies a crafted link, ATBroker.exe resolves it and accesses a file, allowing the attacker to elevate local privileges and compromise system integrity.
Affected Systems
Microsoft Windows products from Windows 10 version 1809 through Windows 11 version 26H1, as well as Windows Server 2019, 2022, and 2025, are affected. All installations that include the Accessibility Infrastructure component with ATBroker.exe enabled are susceptible; the advisory lists the specific CPEs for each OS version.
Risk and Exploitability
Based on the description, it is inferred that attackers must be locally present or possess some local privilege to supply the crafted link. The CVSS score of 7.8 classifies the issue as high severity, and the EPSS score of 3% indicates a small but non‑negligible probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, so no publicly known exploits are documented. When the crafted link is processed by ATBroker.exe, the attacker’s effective privileges are elevated, compromising system integrity.
OpenCVE Enrichment