Executive brief
A vulnerability in Windows Server Backup, a tool used for backing up and restoring data on Windows systems, could allow a local user to gain higher-level administrative permissions. An attacker who already has basic access to the system could exploit this flaw to take full control of the machine, potentially leading to data theft or system-wide disruption. This requires some level of user interaction to be successful.
Technical details
This vulnerability is classified as a link following issue (CWE-59) within the Windows Server Backup component. It occurs when the application fails to properly validate or resolve file links (such as symbolic links or hard links) before performing file operations. A local attacker with low-level privileges can exploit this by creating malicious links that point to sensitive system files, tricking the high-privileged backup service into modifying or accessing them. Successful exploitation requires local access and some user interaction, ultimately allowing the attacker to achieve SYSTEM-level privileges. Microsoft has released security updates to address this issue across affected Windows 10 and 11 versions.
Affected products
- Microsoft Windows 10 Version 21H2 10.0.19044.0 to 10.0.19044.7548
- Microsoft Windows 10 Version 22H2 10.0.19045.0 to 10.0.19045.7548
- Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
- Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
- Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2269
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory