PT-2026-24311 · Microsoft · Windows

James Forshaw

·

Published

2026-03-10

·

Updated

2026-05-26

·

CVE-2026-25187

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows versions (affected versions not specified)
Description A flaw exists in the Winlogon login program of Windows operating systems related to incorrect handling of symbolic links during file access. Exploitation of this issue could allow an attacker to elevate their privileges. The issue involves improper link resolution before file access ('link following') in Winlogon, potentially allowing an authorized attacker to gain elevated privileges locally. Reports indicate a low-privilege attacker can achieve SYSTEM-level access without user interaction. This is considered a significant post-exploitation pathway.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2026-03036
CVE-2026-25187

Affected Products

Windows