Executive brief
Windows Universal Plug and Play (UPnP) Device Host is a system service that enables device discovery and communication on local networks. An authorized attacker can exploit a symlink-following flaw to bypass access controls and read sensitive files on the system, potentially exposing credentials, configuration data, or other confidential information.
Technical details
This vulnerability is a classic symlink/link-following flaw (CWE-59) in Windows UPnP Device Host's file access logic. The component fails to properly validate or resolve symbolic links before accessing files, allowing an attacker with local access or authorization to craft malicious symlinks that redirect file operations to sensitive system locations. The attack requires local or adjacent network access and some level of authorization or user context. By exploiting this, an attacker can read arbitrary files outside their intended access scope, leading to information disclosure. Patches are available from Microsoft.
Affected products
- Microsoft Windows Universal Plug and Play Device Host <UNKNOWN>
Timeline
- 2026-09-08: disclosed