Executive brief
A security vulnerability exists in the Windows Collaborative Translation Framework, a component of the Windows operating system. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to view sensitive data, install malicious software, or disrupt business operations.
Technical details
A privilege escalation vulnerability exists in the Windows Collaborative Translation Framework due to improper link resolution before file access (CWE-59). An attacker with local access and low-level privileges can exploit this by creating symbolic links or junctions that redirect file operations performed by a higher-privileged process to a target file of the attacker's choosing. Successful exploitation allows the attacker to gain SYSTEM-level privileges on the affected host. The vulnerability is tracked as CVE-2026-45586 and was disclosed by Microsoft.
Affected products
- Microsoft Windows Collaborative Translation Framework
Timeline
- 2026-06-09: disclosed: Initial advisory publication by Microsoft and NVD.