Impact
Improper link resolution before file access in Windows Management Services allows a local attacker with authorized access to cause the service to terminate or become unavailable, disrupting management operations. The flaw can be triggered by supplying a crafted link that the service incorrectly follows, leading to a denial of service without compromising system integrity or confidentiality. This behavior aligns with CWE‑59, which involves improper handling of symbolic links or similar filesystem constructs.
Affected Systems
Microsoft Windows 11 24H2, 25H2, and 26H1 are impacted. The 24H2 and 25H2 releases on arm64 architecture and the 26H1 release on x64 architecture contain the flaw.
Risk and Exploitability
The CVSS score of 5.5 indicates moderate severity, while an EPSS score of less than 1% suggests low exploitation probability. The vulnerability is not listed in the CISA KEV catalog and requires local authorized access, limiting the threat surface to users or processes with legitimate privileges. Overall risk is moderate, but the flaw should be remediated promptly.
OpenCVE Enrichment