Junglewise Threat Intelligence

CVE-2026-45586: Microsoft Windows Collaborative Translation Framework privilege escalation

CVE-2026-45586 · Severity: high · CVSS 7.8 · Published 2026-06-09

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Collaborative Translation Framework, a component of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.

Technical details

A privilege escalation vulnerability exists in the Windows Collaborative Translation Framework due to improper link resolution before file access (CWE-59). An attacker with local access and low-level privileges can exploit this by creating symbolic links or junctions that redirect file operations performed by a higher-privileged process to a target file of the attacker's choosing. Successful exploitation allows the attacker to gain SYSTEM-level privileges on the affected host. The vulnerability is tracked as CVE-2026-45586 and was disclosed by Microsoft.

Affected products

  • Microsoft Windows Collaborative Translation Framework

Timeline

  • 2026-06-09: disclosed: Initial advisory publication by Microsoft and NVD.

References