logo

New Windows CTF 0-Day Vulnerability Lets Attackers Gain Elevated Privileges

ID: 8d83288d-14d0-5477-b557-ae65b68f8101

STIX ID: report--8d83288d-14d0-5477-b557-ae65b68f8101

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-06-10

Date Updated: 2026-06-10

Author: Divya

...
...

**Microsoft disclosed CVE-2026-45586**, a Windows CTFMON zero-day elevation-of-privilege vulnerability (CVSS 7.8) caused by improper link resolution/symbolic link handling; it requires local low-privileged access, has low attack complexity with no user interaction, can yield high impact (C/H/I/A), and organizations are advised to apply patches, monitor CTFMON.exe and symbolic link activity, and enforce least-privilege controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.