Executive brief
A security vulnerability exists in the Windows Winlogon component, which manages user logins and logouts. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.
Technical details
A local privilege escalation vulnerability exists in the Microsoft Windows Winlogon component due to improper link resolution (CWE-59). The flaw occurs when the service fails to properly validate file links (such as symbolic links or hard links) before performing file operations. An authenticated attacker with low-level privileges can exploit this by creating a specially crafted link to a protected system file. When Winlogon interacts with the link, it may perform actions on the target file with SYSTEM-level permissions, allowing the attacker to achieve a full compromise of the host. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.
- 2026-06-09: patched: Security updates made available via Microsoft Update Guide.