Executive brief
A security vulnerability exists in the Windows component responsible for managing scheduled tasks. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, change system settings, or disrupt operations.
Technical details
A local privilege escalation vulnerability exists in the Host Process for Windows Tasks (taskhostw.exe) due to improper link resolution (CWE-59). An attacker with low-privileged local access can exploit this by creating symbolic links or junctions that the process follows before performing file operations. By redirecting these operations to protected system files, the attacker can achieve arbitrary file manipulation or code execution with SYSTEM privileges. The vulnerability is addressed in the January 2026 Microsoft security updates.
Affected products
- Microsoft Windows 11 Version 24H2 Up to (excluding) 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 Up to (excluding) 10.0.26200.7623
- Microsoft Windows Server 2025 Up to (excluding) 10.0.26100.32230
Timeline
- 2026-01-13: disclosed
- 2026-01-13: patched