CVE-2026-69289
massLocal Privilege Escalation via Link Following in Windows Setup Files Cleanup
CVE-2026-69289 is a link-following flaw (CWE-59) in the Windows Setup Files Cleanup component, in which the cleanup routine fails to properly resolve links before accessing files. An authorized local attacker with low privileges can place an attacker-controlled link (such as a symlink or junction) in a location the cleanup process traverses, causing elevated file operations to follow that link. Successful exploitation yields local elevation of privilege with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 7.8, AV:L/PR:L/UI:N). The affected scope includes Windows systems running the Setup Files Cleanup component; the available data does not specify an affected version range, so defenders should treat supported Windows releases as potentially in scope pending Microsoft's advisory. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Monitor Microsoft's advisory to identify the affected Windows builds and install the corresponding Windows cumulative security update as soon as it is released, verifying deployment through Windows Update or your patch management system. Until patched, restrict local interactive sign-in and write permissions in directories traversed by setup cleanup routines to trusted users, prioritizing shared or multi-user systems. Given no known exploitation, no public PoC, and low EPSS, routine patch-cycle handling is reasonable absent further vendor guidance.
| Microsoft Windows (Setup Files Cleanup component) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-59
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.