Description
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: Yes
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Improper link resolution before file access in the Windows Update stack allows an authorized local user to elevate privileges. The flaw arises from following symbolic links without proper checks, enabling a local attacker to gain higher access rights on the system. The primary impact is local privilege escalation, classified under CWE-284, and can lead to unauthorized changes or execution with elevated privileges.

Affected Systems

Microsoft Windows 11 23H2, 24H2, 25H2, and 26H1, as well as Windows Server 2025 (including Server Core). These operating systems, for both x64 and arm64 architectures where applicable, are affected by the vulnerability.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level, but the EPSS score is not available, and the vulnerability is listed in the CISA KEV catalog. This status indicates that the vulnerability is actively exploited or exploited in the wild, raising the risk level. Exploitation requires local authorized user privileges; there is no publicly available remote vector. Consequently, the risk remains significant for users with administrative access, while general public exposure is limited.

Generated by OpenCVE AI on September 9, 2026 at 20:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft update that contains the fix for CVE-2026-81963 on all affected Windows 11 and Windows Server 2025 installations.
  • Remove or disable any local accounts that possess administrative privileges unless they are essential for normal operation.
  • Enable and monitor system audit logs for abnormal file operations or privilege escalation attempts to detect potential exploitation attempts early.

Generated by OpenCVE AI on September 9, 2026 at 20:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Tue, 08 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 08 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-09-08T00:00:00+00:00', 'dueDate': '2026-09-22T00:00:00+00:00'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Title Windows Update Stack Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-284
CWE-59
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-25T21:39:00.093Z

Reserved: 2026-08-27T20:58:07.631Z

Link: CVE-2026-81963

cve-icon Vulnrichment

Updated: 2026-09-08T17:40:05.343Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T18:21:00.090

Modified: 2026-09-09T05:18:17.173

Link: CVE-2026-81963

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-09T20:30:15Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')