Junglewise Threat Intelligence

CVE-2026-42989: Microsoft Windows privilege escalation in Winlogon

CVE-2026-42989 · Severity: high · CVSS 7.8 · Published 2026-06-09

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Winlogon component, which manages user logins and logouts. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A local privilege escalation vulnerability exists in the Microsoft Windows Winlogon component due to improper link resolution (CWE-59). The flaw occurs when the service fails to properly validate file links (such as symbolic links or hard links) before performing file operations. An authenticated attacker with low-level privileges can exploit this by creating a specially crafted link to a protected system file. When Winlogon interacts with the link, it may perform actions on the target file with SYSTEM-level permissions, allowing the attacker to achieve a full compromise of the host. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows

Timeline

  • 2026-06-09: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-06-09: patched: Security updates made available via Microsoft Update Guide.

References