CVE-2026-25187

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

high 7.8 CVSS 3.1
Published: Mar 10, 2026
Modified: May 26, 2026
Vendor: Microsoft
Product: Windows 10 1607
Versions: r2

Description

Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.

References

Related CVEs