Description
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
Problem types
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Product status
References
www.vicarius.io/...e-vulnerability-in-windows-update-service
www.vicarius.io/...e-vulnerability-in-windows-update-service
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48799 (Windows Update Service Elevation of Privilege Vulnerability)