Executive brief
Microsoft PC Manager, a tool used for system maintenance and performance optimization, contains a security flaw that could allow a user with limited access to gain full control over a computer. By exploiting how the application handles file shortcuts, an attacker who already has a basic account on the system can escalate their permissions to a higher level. This could lead to unauthorized access to sensitive data, system-wide changes, or the installation of malicious software.
Technical details
A privilege escalation vulnerability exists in Microsoft PC Manager due to improper link resolution before file access (CWE-59). The flaw allows a local attacker with low-level privileges to create symbolic links or junctions that redirect the application's file operations to protected system locations. Because the application performs these operations with higher privileges, the attacker can manipulate system files to achieve a full privilege escalation. The vulnerability affects versions 1.0.0 through 3.22.1.0 and has been addressed in subsequent updates.
Affected products
- Microsoft PC Manager 1.0.0 to 3.22.1.0
Timeline
- 2026-07-14: disclosed: Initial publication of CVE-2026-50438 by Microsoft.
- 2026-07-14: advisory: NVD entry created.