CVE-2026-72971: Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Other sources
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2704Patch KB5121000
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72971?
CVE-2026-72971 has a medium severity rating of 5.5.
What systems are affected by CVE-2026-72971?
CVE-2026-72971 affects Microsoft Windows 11 and the Windows Container Isolation FS Filter Driver (unionfs.sys).
How can I fix CVE-2026-72971?
To fix CVE-2026-72971, install the latest security updates provided by Microsoft for Windows 11.
Who can exploit CVE-2026-72971?
CVE-2026-72971 can be exploited by an authorized attacker with local access to the system.
What does CVE-2026-72971 involve?
CVE-2026-72971 involves improper link resolution which allows for file tampering through the unionfs.sys driver.