Executive brief
Windows Setup Files Cleanup is a system utility for removing temporary installation files. An authorized local user can exploit improper symlink handling to execute code with elevated privileges, potentially gaining full system control and compromising all data on the machine.
Technical details
The vulnerability is a symlink/link-following flaw (CWE-59) in Windows Setup Files Cleanup. An attacker with local access and authorization can craft malicious symbolic links that the cleanup utility follows during file operations, allowing arbitrary file write or code execution with elevated privileges. The attack requires local access and prior authorization on the system. Microsoft has released a security patch to address the improper link resolution before file access.
Affected products
- Microsoft Windows Setup Files Cleanup <UNKNOWN>
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory