Junglewise Threat Intelligence

CVE-2026-70019: Microsoft Windows hard link in Compressed Folder information disclosure

CVE-2026-70019 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Windows Compressed Folder (the built-in ZIP utility) contains a hard link vulnerability that allows an attacker to disclose sensitive information over a network. An unauthorized attacker can exploit this flaw to access files that should be restricted, potentially exposing confidential data stored on affected systems.

Technical details

The vulnerability exists in Windows Compressed Folder's handling of hard links, which are special file references that point directly to file data on disk. An attacker can craft a malicious compressed archive containing specially constructed hard links that, when extracted, bypass intended access controls and expose information over the network. The attack is network-reachable and does not require authentication or user interaction beyond extracting a malicious archive. This allows information disclosure without requiring local system access.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats