CVE-2026-25187
vulnerability analysis and mitigation

Overview

CVE-2026-25187 is a local privilege escalation vulnerability in the Windows Winlogon component caused by improper link resolution before file access (link following). An authenticated attacker with low privileges can exploit this flaw to elevate privileges locally without requiring user interaction. The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update. It affects a broad range of Windows products including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2012 through 2025. The CVSS v3.1 base score is 7.8 (High) (Microsoft MSRC).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), where the Winlogon process fails to properly validate symbolic links or junctions before accessing files, allowing an attacker to redirect file operations to unintended targets. The attack vector is local, requiring only low privileges and no user interaction, making it straightforward to exploit once an attacker has a foothold on the system. The vulnerability is associated with CAPEC-132 (Symlink Attack) and MITRE ATT&CK techniques T1547.009 (Shortcut Modification) and T1574.010 (Services File Permissions Weakness). In May 2026, 0patch released micropatches for this vulnerability alongside related Winlogon accessibility infrastructure flaws (CVE-2026-24291, CVE-2026-25186), indicating the vulnerability class was studied in depth by third-party researchers (Microsoft MSRC, 0patch Blog).

Impact

Successful exploitation allows a low-privileged authenticated attacker to escalate to SYSTEM-level privileges on the affected Windows machine, representing a complete local system compromise. This grants full control over the operating system, enabling the attacker to install malware, modify system configurations, access all local data, and potentially facilitate lateral movement within a network. The vulnerability affects a wide range of Windows deployments — from legacy Windows Server 2012 to the latest Windows 11 26H1 and Windows Server 2025 — significantly broadening the potential attack surface (Microsoft MSRC).

Exploitation steps

  1. Gain initial access: Obtain a low-privileged authenticated user account on the target Windows system (e.g., via phishing, credential theft, or exploitation of another vulnerability).
  2. Identify the vulnerable Winlogon file access path: Analyze the Winlogon process to identify file system operations that follow symbolic links or junctions without proper validation — the specific file path targeted by the link-following flaw.
  3. Create a malicious symbolic link or junction: Using tools such as CreateSymbolicLink (Windows API) or utilities like mklink, create a symlink or directory junction pointing from the path Winlogon accesses to a privileged target location (e.g., a system file or registry hive).
  4. Trigger the vulnerable Winlogon code path: Cause Winlogon to execute the vulnerable file access operation, which follows the attacker-controlled symlink and performs a privileged file operation on the attacker-specified target.
  5. Achieve SYSTEM-level privilege: The misdirected file operation (e.g., write, overwrite, or permission change) on the privileged target allows the attacker to escalate to SYSTEM, for example by overwriting a service binary or planting a malicious DLL that executes in a SYSTEM context (Microsoft MSRC, 0patch Blog).

Indicators of compromise

  • Process: Unusual child processes spawned from winlogon.exe, such as cmd.exe, powershell.exe, or other shells running under the SYSTEM account initiated by a low-privileged user session.
  • File System: Unexpected symbolic links or directory junctions created in directories accessed by Winlogon; newly created or modified files in system directories (e.g., %SystemRoot%\System32) with timestamps correlating to non-administrative user activity.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 — Special privileges assigned to new logon) for accounts that should not hold elevated rights; Event ID 4688 showing process creation with elevated tokens from unexpected parent processes.
  • Registry: Unexpected modifications to HKLM\SYSTEM or HKLM\SOFTWARE registry keys by non-administrative accounts, potentially indicating post-exploitation persistence activity.

Mitigation and workarounds

Microsoft released patches on March 10, 2026, as part of the March 2026 Patch Tuesday update. Organizations should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 21H2/22H2 → 10.0.19044.7058 / 10.0.19045.7058; Windows 10 1809 → 10.0.17763.8511; Windows 10 1607 → 10.0.14393.8957; Windows 11 23H2 → 10.0.22631.6783; Windows 11 24H2 → 10.0.26100.7979; Windows 11 25H2 → 10.0.26200.7979; Windows 11 26H1 → 10.0.28000.1719; Windows Server 2016 → 10.0.14393.8957; Windows Server 2019 → 10.0.17763.8511; Windows Server 2022 → 10.0.20348.4830; Windows Server 2022 23H2 → 10.0.25398.2207; Windows Server 2025 → 10.0.26100.32463. For systems that cannot be immediately patched, 0patch released unofficial micropatches in May 2026 as a temporary mitigation (Microsoft MSRC, 0patch Blog). Restricting local user access and monitoring for symlink creation in sensitive directories can reduce risk until patching is complete.

Community reactions

CVE-2026-25187 was covered as part of broader March 2026 Patch Tuesday roundups by major security outlets including Krebs on Security, The Hacker News, Rapid7, Qualys, Talos Intelligence, and Zero Day Initiative, though it did not receive individual spotlight coverage given the absence of active exploitation (Krebs on Security, Qualys Blog). The March 2026 Patch Tuesday was widely noted as the first in six months without any actively exploited zero-days, which tempered urgency around individual vulnerabilities in the batch. In May 2026, 0patch drew renewed attention to this CVE by releasing micropatches alongside related Winlogon accessibility infrastructure flaws, generating discussion on Reddit and Bluesky (0patch Blog). Recorded Future's March 2026 CVE landscape report identified this vulnerability among high-impact issues from the month (Recorded Future).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management