Junglewise Threat Intelligence

CVE-2026-49180: Microsoft Windows UPnP link following in upnp.dll

CVE-2026-49180 · Severity: medium · CVSS 5.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Universal Plug and Play (UPnP) component, which is used by the operating system to discover and connect to network devices like printers and routers. An attacker who already has basic access to a computer could exploit this flaw to gain unauthorized access to sensitive information or modify files they should not be able to reach. This could lead to a breach of data confidentiality or system integrity on the affected machine.

Technical details

A vulnerability classified as CWE-59 (Improper Link Resolution Before File Access) exists in the Windows Universal Plug and Play (UPnP) service, specifically within upnp.dll. The flaw occurs when the component fails to properly validate file links (such as symbolic links or hard links) before performing file operations. A local attacker with low-privileged access can exploit this by creating a malicious link that points to a sensitive system file, tricking the UPnP service into accessing or modifying that file with its higher-level permissions. This is a local attack vector requiring prior authentication on the target system. Microsoft has released security updates to address this issue across various Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats