Impact
Improper link resolution before file access in the Windows Setup Files Cleanup utility allows an authorized local user to elevate privileges; the flaw permits following symbolic or shortcut links that bypass intended access control checks. This results in the user gaining administrative rights on the affected system. The weakness is classed as CWE‑59, indicating an issue with path traversal or improper handling of filesystem links.
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 releases 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including their Server Core editions.
Risk and Exploitability
Based on the description, it is inferred that the attack can only be carried out from within the host by a user who has local access and can place a crafted symbolic or shortcut link in the cleanup process’ directory. The exploitation path is therefore a local privilege escalation. The CVSS score is 7.8, indicating moderate‑to‑high severity, and the lack of an EPSS score or KEV listing suggests no widespread exploitation yet. Once the crafted link is processed by the cleanup service, it follows with elevated privileges, potentially granting the attacker full administrative access.
OpenCVE Enrichment