Description

Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.

Severity (CVSS)

Base score5.5
SeverityMedium
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C
Provided byCNA

Weaknesses

  • CWE-59 — CWE-59: Improper Link Resolution Before File Access ('Link Following')

Affected products

VendorProductVersions
MicrosoftWindows 10 Version 160710.0.14393.0 to <10.0.14393.9339
MicrosoftWindows 10 Version 180910.0.17763.0 to <10.0.17763.9020
MicrosoftWindows 10 Version 21H210.0.19044.0 to <10.0.19044.7548
MicrosoftWindows 10 Version 22H210.0.19045.0 to <10.0.19045.7548
MicrosoftWindows 11 Version 24H210.0.26100.0 to <10.0.26100.8875
MicrosoftWindows 11 Version 25H210.0.26200.0 to <10.0.26200.8875
MicrosoftWindows 11 version 26H110.0.28000.0 to <10.0.28000.2269
MicrosoftWindows Server 20126.2.9200.0 to <6.2.9200.26226
MicrosoftWindows Server 2012 (Server Core installation)6.2.9200.0 to <6.2.9200.26226
MicrosoftWindows Server 2012 R26.3.9600.0 to <6.3.9600.23291
MicrosoftWindows Server 2012 R2 (Server Core installation)6.3.9600.0 to <6.3.9600.23291
MicrosoftWindows Server 201610.0.14393.0 to <10.0.14393.9339
MicrosoftWindows Server 2016 (Server Core installation)10.0.14393.0 to <10.0.14393.9339
MicrosoftWindows Server 201910.0.17763.0 to <10.0.17763.9020
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 to <10.0.17763.9020
MicrosoftWindows Server 202210.0.20348.0 to <10.0.20348.5386
MicrosoftWindows Server 202510.0.26100.0 to <10.0.26100.33158
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0 to <10.0.26100.33158

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.