New Windows CTF 0-Day Vulnerability Lets Attackers Gain Elevated Privileges
ID: 8d83288d-14d0-5477-b557-ae65b68f8101
STIX ID: report--8d83288d-14d0-5477-b557-ae65b68f8101
Feed Name: GBHackers
Threat Score
**Microsoft disclosed CVE-2026-45586**, a Windows CTFMON zero-day elevation-of-privilege vulnerability (CVSS 7.8) caused by improper link resolution/symbolic link handling; it requires local low-privileged access, has low attack complexity with no user interaction, can yield high impact (C/H/I/A), and organizations are advised to apply patches, monitor CTFMON.exe and symbolic link activity, and enforce least-privilege controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
