Executive brief
Microsoft PC Manager, a tool used to optimize and manage Windows system performance, contains a security flaw that could allow a user with limited access to gain full administrative control over a computer. By exploiting how the application handles file links, an attacker who already has a basic account on the machine can bypass security restrictions to access or modify sensitive system files. This could lead to a complete compromise of the affected device, including the theft of data or the installation of malicious software.
Technical details
A privilege escalation vulnerability exists in Microsoft PC Manager due to improper link resolution (CWE-59), commonly known as a symlink or link-following attack. The application fails to properly validate file paths before performing file operations, allowing a local attacker with low privileges to create symbolic links or junctions that redirect the application's high-privileged file actions to sensitive system locations. By successfully exploiting this flaw, an attacker can achieve SYSTEM-level privileges on the local machine. The vulnerability affects versions 1.0.0 through 3.21.6.0 and has been addressed in subsequent updates.
Affected products
- Microsoft PC Manager 1.0.0 to 3.21.6.0
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory