ZeroHour

CVE-2026-69289

mass

Local Privilege Escalation via Link Following in Windows Setup Files Cleanup

CVSS 3.1
7.8 high
EPSS
<1%p29
Published
()
Modified
AI analysis

CVE-2026-69289 is a link-following flaw (CWE-59) in the Windows Setup Files Cleanup component, in which the cleanup routine fails to properly resolve links before accessing files. An authorized local attacker with low privileges can place an attacker-controlled link (such as a symlink or junction) in a location the cleanup process traverses, causing elevated file operations to follow that link. Successful exploitation yields local elevation of privilege with high impact to confidentiality, integrity, and availability (CVSS 3.1 score 7.8, AV:L/PR:L/UI:N). The affected scope includes Windows systems running the Setup Files Cleanup component; the available data does not specify an affected version range, so defenders should treat supported Windows releases as potentially in scope pending Microsoft's advisory. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation exists, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Monitor Microsoft's advisory to identify the affected Windows builds and install the corresponding Windows cumulative security update as soon as it is released, verifying deployment through Windows Update or your patch management system. Until patched, restrict local interactive sign-in and write permissions in directories traversed by setup cleanup routines to trusted users, prioritizing shared or multi-user systems. Given no known exploitation, no public PoC, and low EPSS, routine patch-cycle handling is reasonable absent further vendor guidance.

Affected
Microsoft Windows (Setup Files Cleanup component)
Estimated exposure
mass≈1 billion Windows devices potentially affected (global Windows install base; affected builds not yet scoped) — Windows runs on well over one billion active devices worldwide, and elevation-of-privilege flaws in built-in Windows components typically apply across supported versions until the vendor publishes narrower scoping.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.

Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.