ZeroHour

CVE-2026-69379

mass

NTFS link-following flaw enables local privilege escalation on Windows

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-69379 is an improper link resolution (CWE-59) flaw in the Windows NTFS file system, where file access through a link can be granted without correctly validating the link's target. An attacker who already holds a low-privileged account on a Windows machine can plant or manipulate a link (such as a junction or symbolic link) so that a privileged process follows it to an unintended file; the high attack complexity (AC:H) indicates specific local conditions are needed to trigger it. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability on the compromised host. Any Windows system using NTFS is potentially affected, but the available data does not specify affected builds, so defenders should consult Microsoft's advisory for exact version ranges. There is no public proof of concept, no CISA KEV listing, and a low 0.3% EPSS, indicating no confirmed exploitation to date.

What to do: Apply the Microsoft cumulative/security update for Windows that remediates CVE-2026-69379 as soon as it is available, checking Microsoft's advisory for the exact affected builds since version details are not in the current data. Because exploitation requires an existing local foothold, restrict interactive logon and standard-user rights on shared or multi-user servers as an interim mitigation, and monitor for unexpected local privilege escalation. Given no public PoC and low EPSS, routine patching cadence is sufficient; no emergency action is required.

Affected
Microsoft Windows (NTFS component)
Estimated exposure
mass≈1 billion+ Windows installations (global Windows desktop/server installed base) — Windows runs on well over a billion active devices worldwide as the dominant client and server OS, and the flaw resides in the NTFS component used across Windows editions, though exact affected builds are not listed in the source data.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2025
Weakness
CWE-59
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.