Description
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Published: 2026-08-11
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper link resolution before file access in Windows Management Services allows a local attacker with authorized access to cause the service to terminate or become unavailable, disrupting management operations. The flaw can be triggered by supplying a crafted link that the service incorrectly follows, leading to a denial of service without compromising system integrity or confidentiality. This behavior aligns with CWE‑59, which involves improper handling of symbolic links or similar filesystem constructs.

Affected Systems

Microsoft Windows 11 24H2, 25H2, and 26H1 are impacted. The 24H2 and 25H2 releases on arm64 architecture and the 26H1 release on x64 architecture contain the flaw.

Risk and Exploitability

The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1% suggests low exploitation probability. The vulnerability is not listed in the CISA KEV catalog and requires local authorized access, limiting the threat surface to users or processes with legitimate privileges. Overall risk is moderate, but the flaw should be remediated promptly.

Generated by OpenCVE AI on August 12, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Windows 11 to the latest cumulative update that includes the fix for CVE‑2026‑70348 via Windows Update or Microsoft Defender Security Center.
  • Verify that the Windows Management Services service is running with the smallest set of privileges necessary, and restrict service access to trusted administrators only.
  • Monitor the Windows Management Services event logs for unexpected shutdowns or restarts and investigate any anomalies promptly.

Generated by OpenCVE AI on August 12, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*

Fri, 14 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Vendors & Products Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Title Windows Management Services Denial of Service Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-59
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:06:21.822Z

Reserved: 2026-08-04T00:04:56.037Z

Link: CVE-2026-70348

cve-icon Vulnrichment

Updated: 2026-08-12T13:50:28.865Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:19:12.513

Modified: 2026-08-14T18:21:06.093

Link: CVE-2026-70348

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T12:45:16Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')