Impact
Improper link resolution before file access in Microsoft OneDrive for macOS allows a user with local access to elevate privileges. The vulnerability is classified as CWE‑59 and can give the attacker higher privileges on the machine without any external network interaction.
Affected Systems
Microsoft OneDrive for macOS is affected. Any installed version that has not received the Microsoft update addressing CVE‑2026‑65680 should be considered vulnerable until the patch is applied.
Risk and Exploitability
The CVSS score of 6.7 indicates medium severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not a known widely exploited threat. The attack requires local user privileges and relies on manipulating link resolution within the OneDrive environment, making it a local privilege escalation scenario with a moderate risk profile.
OpenCVE Enrichment