Executive brief
Windows Container Manager Service is a system component responsible for managing containerized applications in Windows environments. An authorized attacker can exploit improper link resolution ('link following') to bypass local security features, potentially gaining elevated access or circumventing access controls on the affected system.
Technical details
This vulnerability is a symlink/hardlink following flaw (CWE-59) in Windows Container Manager Service that fails to properly resolve links before file access operations. An authenticated local attacker can exploit this to bypass security features by crafting malicious symbolic or hard links pointing to protected resources. The attack requires local access and valid credentials on the system. Successful exploitation allows an attacker to access or modify files they should not have permission to access, potentially circumventing security controls. A patch from Microsoft is expected to be available through standard Windows Update channels.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed