Junglewise Threat Intelligence

CVE-2026-58636: Microsoft PC Manager privilege escalation via improper link resolution

CVE-2026-58636 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft PC Manager. Vendors: Microsoft.

Executive brief

Microsoft PC Manager, a tool used to optimize and manage Windows system performance, contains a security flaw that could allow a user with limited access to gain full administrative control over a computer. By exploiting how the application handles file links, an attacker who already has a basic account on the machine can bypass security restrictions to access or modify sensitive system files. This could lead to a complete compromise of the affected device, including the theft of data or the installation of malicious software.

Technical details

A privilege escalation vulnerability exists in Microsoft PC Manager due to improper link resolution (CWE-59), commonly known as a symlink or link-following attack. The application fails to properly validate file paths before performing file operations, allowing a local attacker with low privileges to create symbolic links or junctions that redirect the application's high-privileged file actions to sensitive system locations. By successfully exploiting this flaw, an attacker can achieve SYSTEM-level privileges on the local machine. The vulnerability affects versions 1.0.0 through 3.21.6.0 and has been addressed in subsequent updates.

Affected products

  • Microsoft PC Manager 1.0.0 to 3.21.6.0

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats