CVE-2026-20941Link Following in Microsoft Windows 11 Version 24h2

CWE-59Link Following5 documents5 sources
Severity
7.8HIGHNVD
EPSS
0.0%
top 88.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 13

Description

Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages6 packages

NVDmicrosoft/windows< 10.0.26100.32230
NVDmicrosoft/windows_11_24h2< 10.0.26100.7623
NVDmicrosoft/windows_11_25h2< 10.0.26200.7623
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.32230
CVEListV5microsoft/windows_11_version_24h210.0.26100.010.0.26100.7623

🔴Vulnerability Details

2
GHSA
GHSA-x52h-wv3h-pxc9: Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges l2026-01-13
CVEList
Host Process for Windows Tasks Elevation of Privilege Vulnerability2026-01-13

📋Vendor Advisories

1
Microsoft
Host Process for Windows Tasks Elevation of Privilege Vulnerability2026-01-13

🕵️Threat Intelligence

1
Wiz
CVE-2026-20941 Impact, Exploitability, and Mitigation Steps | Wiz