CVE-2026-81963

HIGH Status: Analyzed

CVSS Scores

CVSS v3.x Base Score
7.8
HIGH

Description

Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Published
September 8, 2026 6:21 PM
Last Modified
September 8, 2026 7:28 PM
Source
[email protected]

Weaknesses (CWE)

CWE-59 CWE-284

References

Affected Configurations

[
    {
        "nodes": [
            {
                "operator": "OR",
                "negate": false,
                "cpeMatch": [
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.22631.7582",
                        "matchCriteriaId": "97D353CE-F9A4-46B5-BC5C-BF422E10785D"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.22631.7582",
                        "matchCriteriaId": "A2B42421-4694-4879-A69B-6A9192E2CFB8"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.26100.9445",
                        "matchCriteriaId": "990434BE-FE81-48CC-8803-94FAEB694DE2"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.26100.9445",
                        "matchCriteriaId": "045BBF02-6FDD-44D4-B278-0C52A5406956"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.26200.9445",
                        "matchCriteriaId": "948460EF-4053-4106-8D9E-4EDC3BF7B682"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.26200.9445",
                        "matchCriteriaId": "D4F1D717-582C-446B-B90F-1D25028DA77F"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*",
                        "versionEndExcluding": "10.0.28000.2954",
                        "matchCriteriaId": "4B46D2B8-7E89-4818-862C-30B9751BA6EA"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*",
                        "versionEndExcluding": "10.0.28000.2954",
                        "matchCriteriaId": "165C7909-F15B-4328-A175-B9FEF3BEB82D"
                    },
                    {
                        "vulnerable": true,
                        "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                        "versionEndExcluding": "10.0.26100.33438",
                        "matchCriteriaId": "48D75543-6B91-41E9-A1FB-1A09A2CBD738"
                    }
                ]
            }
        ]
    }
]

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.