CVE-2026-69379: Windows NTFS Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows NTFS allows an authorized attacker to elevate privileges locally.
Other sources
Windows NTFS Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must already be authorized on the affected Windows system and have local access. The issue is not described as remotely exploitable.
What level of access does an attacker need before exploitation?
The attacker needs low privileges and local access. No user interaction is required once those prerequisites are met.
What could successful exploitation allow?
Successful exploitation can elevate the attacker's privileges. The supplied severity vector indicates high impact to confidentiality, integrity, and availability.
How difficult is exploitation expected to be?
The supplied vector rates attack complexity as high, indicating exploitation requires conditions beyond simply having local low-privileged access.