CVE-2026-81963
9.5 CISA KEVMicrosoft · Windows
A link following vulnerability in the Windows Update Stack allows a local attacker with authorized access to elevate privileges on the affected system.
Executive summary
A critical privilege escalation vulnerability in the Windows Update Stack is currently being exploited in the wild, posing a severe risk to system integrity and security.
Vulnerability
The vulnerability involves improper link resolution before file access, which occurs within the Windows Update Stack. An attacker with low-level local privileges can manipulate link resolutions to achieve unauthorized privilege escalation on the host system.
Business impact
The exploitation of this flaw enables a local user to gain higher-level permissions, potentially leading to full system compromise. Given the CVSS score of 9.5 and confirmed active exploitation in the wild, this vulnerability represents an immediate threat to the confidentiality, integrity, and availability of sensitive business data and infrastructure.
Remediation
Immediate Action: Apply the vendor-provided updates immediately to the affected versions listed above. Ensure that all systems running Windows 11 or Windows Server 2025 are patched to the specific build numbers identified as fixed.
Proactive Monitoring: Monitor system logs for unauthorized attempts to access or modify sensitive system files, particularly those associated with the Windows Update process. Review security event logs for signs of suspicious privilege escalation activity.
Compensating Controls: While there is no direct virtual patch for this local privilege escalation, implement strict least-privilege access controls to limit the number of users who can interact with the system locally. Restrict physical and remote interactive access to critical servers.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The presence of this vulnerability in the CISA Known Exploited Vulnerabilities catalog necessitates immediate attention. IT teams should prioritize the deployment of the specified security updates to prevent unauthorized privilege escalation and protect critical infrastructure from active exploitation.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Added to CISA KEV confirmed active exploitation
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief kev section
Sources
- Windows Update Stack Elevation of Privilege Vulnerability Vendor advisory