CVE-2026-69289
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privi
CVSS
7.8
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-59
Not enough EPSS history yet.
Improper link resolution before file access ('link following') in Windows Setup Files Cleanup allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-839997.0 HIG—
———Improper link resolution before file access ('link following') in Windows Resilient File System (ReFS) Deduplication Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-819637.8 HIG—
———Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.4hCVE-2026-705638.1 HIG—
———Improper link resolution before file access ('link following') in Windows Shell allows an unauthorized attacker to perform spoofing over a network.4hCVE-2026-697714.7 MED—
———Improper link resolution before file access ('link following') in Windows Container Manager Service allows an authorized attacker to bypass a security feature locally.4hCVE-2026-694254.7 MED—
———Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to perform tampering locally.4hCVE-2026-693797.0 HIG—
———Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.4h