Junglewise Threat Intelligence

CVE-2026-25187: Microsoft Windows Winlogon privilege escalation via link following

CVE-2026-25187 · Severity: high · CVSS 7.8 · Published 2026-03-10

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in Winlogon, a core Windows component responsible for managing user logins and sessions. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to bypass security restrictions, access sensitive data, or install malicious software across the corporate network.

Technical details

A privilege escalation vulnerability exists in the Windows Winlogon component due to improper link resolution before file access (CWE-59). The flaw allows a locally authenticated attacker with low privileges to create symbolic links or junctions that redirect file operations performed by the high-privileged Winlogon process. By successfully exploiting this 'link following' vulnerability, an attacker can achieve SYSTEM-level privileges on the affected host. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2012 through 2025. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 All versions
  • Microsoft Windows Server 2019 All versions

Timeline

  • 2026-03-10: disclosed: Initial disclosure by Microsoft
  • 2026-03-10: advisory: NVD published the CVE record
  • 2026-05-26: other: NVD record updated with enrichment data and community references

References

Related threats