5.5
CVE-2026-72971
- EPSS 0.36%
- Veröffentlicht 11.08.2026 17:05:40
- Zuletzt bearbeitet 14.08.2026 18:21:30
- Erkennungen
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 11 26h1 HwPlatform arm64 Version < 10.0.28000.2704
Microsoft ≫ Windows 11 26h1 HwPlatform x64 Version < 10.0.28000.2704
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.36% | 0.288 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Microsoft | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
|
CWE-59 Improper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-72971