Impact
This vulnerability is caused by improper link resolution before file access in the Windows User Profile Service, allowing an attacker with local authorization to elevate privileges. The flaw permits a local user to influence the service to follow a supplied symbolic or otherwise linked path, enabling the execution of code with higher privileges than the original user account. The impact is a loss of control over the affected system and potential further compromise of the network if the elevated privileges are used to move laterally.
Affected Systems
Microsoft Windows 10 Version 21H2 and 22H2, Microsoft Windows 11 Versions 23H2, 24H2, 25H2, 26H1, Microsoft Windows Server 2022, Microsoft Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 reflects a high severity risk, with an EPSS score of 2%. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an authenticated local attacker; exploitation requires the ability to place a malicious link within a user profile or a related directory. Because the flaw stems from inadequate path normalization, an attacker can gain privileged access without exploiting additional vulnerabilities, making it relatively easy to use once local access to a target machine is established.
OpenCVE Enrichment