← back
CVE-2026-81963highunder attackCWE-284CWE-59

Windows Update Stack Elevation of Privilege Vulnerability

51Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 7.8epss 0.6%
from disclosure to weapon
Published on NVDSep 8
CISA KEVSep 8
exploitation probability
0.6%top 52% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2026-09-22

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

In short

Windows Update Stack has a vulnerability where it follows symbolic links without proper checks, allowing someone with local access to trick it into accessing files they shouldn't, gaining higher system privileges.

Technical detail

CWE-59 (improper link resolution) in Windows Update Stack fails to validate symlink targets before file operations, enabling privilege escalation via directory traversal. An authorized local attacker can exploit this by creating malicious symlinks to arbitrary files, causing the elevated process to access unintended resources and escalate privileges.

Summary generated and translated by AI from the official description.
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C