CVE-2026-62832
microsoft windows_10_21h2: Improper Link Resolution Before File Access ('Link Following')
Affected
- microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_21h2
lt *..10.0.19044.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_10_22h2
lt *..10.0.19045.7663 - microsoft/windows_11_23h2
lt *..10.0.22631.7517 - microsoft/windows_11_23h2
lt *..10.0.22631.7517 - microsoft/windows_11_24h2
lt *..10.0.26100.9168 - microsoft/windows_11_24h2
lt *..10.0.26100.9168 - microsoft/windows_11_25h2
lt *..10.0.26200.9168 - microsoft/windows_11_25h2
lt *..10.0.26200.9168 - microsoft/windows_11_26h1
lt *..10.0.28000.2704 - microsoft/windows_11_26h1
lt *..10.0.28000.2704 - microsoft/windows_server_2022
lt *..10.0.20348.5499 - microsoft/windows_server_2025
lt *..10.0.26100.33296
Description
Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
Affected operating systems
windows
microsoft / windows_10_21h2
windows
microsoft / windows_10_22h2
windows
microsoft / windows_11_23h2
windows
microsoft / windows_11_24h2
windows
microsoft / windows_11_25h2
windows
microsoft / windows_11_26h1
windows
microsoft / windows_server_2022
windows
microsoft / windows_server_2025
Metrics
Show all metrics
Weakness classes (CWE)
CWE-59Base
Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- New CVE Received2026-08-11 17:18 UTC· secure@microsoft.com
- Affected: Windows 10 Version 21H2, Windows 10 Version 22H2, Windows 11 version 23H2 (+7)
- Description: Improper link resolution before file access ('link following') in Windows User Profile Service allows an authorized attacker to elevate privileges locally.
- CVSS V3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE: CWE-59