CVE-2026-70348: Windows Management Services Denial of Service Vulnerability
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
Other sources
Windows Management Services Denial of Service Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26100.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.9168Fixed in 10.0.26000.9106Patch KB5120994 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000
Event History
Frequently Asked Questions
What is the severity of CVE-2026-70348?
The severity of CVE-2026-70348 is classified as medium with a score of 5.5.
How does CVE-2026-70348 affect Windows Management Services?
CVE-2026-70348 allows an authorized attacker to cause a denial of service in Windows Management Services through improper link resolution.
What systems are impacted by CVE-2026-70348?
CVE-2026-70348 affects Microsoft Windows 11 and Microsoft Windows Management Services.
Who can exploit CVE-2026-70348?
CVE-2026-70348 can be exploited by an authorized attacker with local access to the affected system.
What is the potential impact of CVE-2026-70348?
The potential impact of CVE-2026-70348 is a denial of service, which can disrupt services on the affected system.