Zurück

Windows Update Stack Elevation of Privilege Vulnerability

CVE-2026-81963
Sep 16, 2026

CVE-2026-81963 is a local Elevation of Privilege (EoP) vulnerability in the Windows Update Stack, specifically classified under CWE-59: Improper Link Resolution Before File Access ('Link Following') and CWE-284: Improper Access Control. The defect occurs during the file staging and directory cleanup operations handled by the Windows Update service.

An authenticated attacker with standard local user privileges can exploit this flaw by manipulating file system junctions, symbolic links, or hard links within low-privileged, predictable temporary update staging directories. When the high-privileged Windows Update service (executing under NT AUTHORITY\SYSTEM) processes, writes, or moves installation packages, it improperly follows these user-controlled links without verifying file ownership or destination boundaries. This allows the attacker to redirect privileged file write operations into protected system directories (e.g., System32), facilitating arbitrary file creation, DLL planting, or binary overwrites to execute arbitrary code with full SYSTEM privileges.

Observed exploitation: Active in-the-wild exploitation has been observed. Threat actors leverage this flaw as a secondary-stage privilege escalation mechanism after gaining initial user-level access on endpoints running Windows 11 and Windows Server 2025.

 

Key Details:

·         Vulnerability Type: Local Elevation of Privilege (EoP) / Improper Link Resolution & Improper Access Control (CWE-59 / CWE-284)

·         Affected Versions: Windows 11 (Versions 22H2, 23H2, 24H2) and Windows Server 2025

·         Cause: Improper access control and improper link resolution in the kernel-mode ALPC port message dispatcher

·         Potential Impact: An attacker with authenticated local access can bypass VBS/HVCI mitigations and sandbox isolation, escalate privileges to NT AUTHORITY\SYSTEM, tamper with kernel audit policies, dump DPAPI/LSASS credentials, and facilitate domain lateral movement

·         CVE ID: CVE-2026-81963

Case References:

·         https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963

·         CISA Known Exploited Vulnerabilities (KEV) Catalog (Added September 2026)

Customers are strongly advised to deploy the September 2026 Cumulative Security Updates immediately across all affected Windows 11 and Windows Server 2025 systems. Note: Do NOT attempt to disable Windows ALPC or RPC services via registry modifications, as doing so will cause operating system boot failures.

 

*For any further assistance regarding this issue please contact your sales representative, or create a new support ticket at https://esupport.gigabyte.com