Home
HIGH: 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.0 (custom) before 10.0.26200.6899
affected
10.0.26100.0 (custom) before 10.0.26100.6899
affected
Description
Improper link resolution before file access ('link following') in Windows Health and Optimized Experiences Service allows an authorized attacker to elevate privileges locally.
Problem types
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59241 (Windows Health and Optimized Experiences Elevation of Privilege Vulnerability)