Windows Update Stack Elevation of Privilege Vulnerability
Prioritize patching. It under exploitation confirmed by CISA.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
Windows Update Stack has a vulnerability where it follows symbolic links without proper checks, allowing someone with local access to trick it into accessing files they shouldn't, gaining higher system privileges.
CWE-59 (improper link resolution) in Windows Update Stack fails to validate symlink targets before file operations, enabling privilege escalation via directory traversal. An authorized local attacker can exploit this by creating malicious symlinks to arbitrary files, causing the elevated process to access unintended resources and escalate privileges.