# CVE-2026-61358 — Windows Accessibility Infrastructure `ATBroker.exe` AT-Settings Registry Write Follows Symbolic Link → Elevation of Privilege

---

## Summary

| | |
|---|---|
| **Product** | Windows — `ATBroker.exe` (Windows Accessibility Infrastructure / Assistive Technology Broker) |
| **CVE ID** | CVE-2026-61358 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.8 / 6.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-59: Improper Link Resolution Before File Access ('Link Following') |
| **Delivery** | Local — plant a registry symbolic link at the AT-settings target key |
| **KB / Fixed build (diffed lineage, 23H2)** | KB5120240 — `ATBroker.exe` 10.0.22621.7219 (Win11 23H2 x64) |
| **Equivalent 24H2 fix** | KB5121003 — `ATBroker.exe` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `ATBroker.exe` 10.0.22621.6783 — SHA256 `132f3a0541906249c8ab74a99ce9e24ab1ccafce86e0b842f7ef5bcf5bd918e7` |
| **Post-patch binary** | `ATBroker.exe` 10.0.22621.7219 — SHA256 `49c866dab87f3f0a2e4ba5ed62c094848f6c2920ef95c717b97c50c2953331ec` |
| **Feature flag** | none — the symbolic-link guard is unconditional (not CFR-gated) |
| **Exploitability** | Exploitation More Likely; not publicly disclosed; not exploited (per MSRC) |

> Lineage note: the diff was produced on the **23H2 (build 22621)** pair
> `.6783 → .7219` (KB5120240). Win11 24H2 (26100) ships the **equivalent** fix in
> `ATBroker.exe` 10.0.26100.9168 (KB5121003). CVE-2026-61358 affects both lineages.

---

## Product Description

`ATBroker.exe` is the **Assistive Technology Broker**, a privileged component of the
Windows Accessibility Infrastructure. It launches and manages assistive technologies
(Narrator, Magnifier, etc.) and **copies Assistive-Technology (AT) settings between
registry locations** via `SettingsCopier::CopyATSettings` / `SetRegKeyValue`, which
open a destination key and write values (`RegOpenKeyExW` → `RegSetValueExW`).

---

## Vulnerability Summary

Pre-patch, when `CopyATSettings` / `SetRegKeyValue` wrote an AT-settings value, it
opened the destination registry key and wrote to it **without checking whether that
key was a registry symbolic link**. Because ATBroker performs the copy from a
privileged context, a low-privileged attacker who can influence the destination
location could plant a **registry symbolic link** there so that the privileged write
is **redirected to an attacker-chosen key** (link following, CWE-59) — for example
into a sensitive `HKLM` location — yielding elevation of privilege to **SYSTEM** (per
the MSRC FAQ). MSRC rates exploitation **More Likely**.

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`).
- Plant a registry symbolic link at the key ATBroker will write AT settings to.
- Trigger the AT-settings copy so the privileged write follows the link to a target
  the attacker could not otherwise write.

---

## Vulnerability Details

### Root Cause

The AT-settings registry write opened and wrote the destination key without verifying
it was not a symbolic link, so a planted `REG_LINK` key redirected the privileged
write to an attacker-controlled destination.

### The patch (confirmed — diff, 22621.6783 → 22621.7219)

The patched `CopyATSettings` (subsuming `SetRegKeyValue`) adds an **explicit
symbolic-link check before writing**: it opens the key with `REG_OPTION_OPEN_LINK`
(open the link object itself, do not follow it), queries the special
`SymbolicLinkValue`, and if the key is a registry symbolic link (`REG_LINK`, type 6)
it **aborts with a failure HRESULT instead of writing**:

```c
// SettingsCopier::CopyATSettings (10.0.22621.7219) — PATCHED (from the diff)
uVar5 = RegCreateKeyExW(hKey, lpSubKey, 0, 0, 1, 0x2001f, 0, &local_2a0, &local_2a8);
if (uVar5 == 0) {
    RegCloseKey(local_2a0);
    uVar5 = RegOpenKeyExW(hKey, lpSubKey, 8 /* REG_OPTION_OPEN_LINK */, 0x2001f, &local_2c8);
    if (uVar5 == 0) {
        // does this key carry a SymbolicLinkValue (i.e. is it a registry symlink)?
        uVar5 = RegQueryValueExW(local_2c8, L"SymbolicLinkValue", 0, &local_2c0, 0, &local_2a4);
        if (uVar5 == 0) {
            if (local_2c0 != 6 /* REG_LINK */) goto do_write;
            RegCloseKey(local_2c8);
            uVar5 = 0x800705b8;            // *** symlink detected -> refuse, do NOT write ***
            goto fail;
        }
        if (uVar5 != 2 /* ERROR_FILE_NOT_FOUND: no such value -> not a link */) { ... }
do_write:
        uVar5 = RegSetValueExW(local_2c8, valueName, 0, type, (BYTE*)lpData, cbData);
        RegCloseKey(local_2c8);
    }
}
```

Pre-patch, `SetRegKeyValue` simply did `RegOpenKeyExW(...)` then
`RegSetValueExW(...)` with no link check, so a `REG_LINK` at the destination would be
followed. With the added `REG_OPTION_OPEN_LINK` open plus the `SymbolicLinkValue` /
`REG_LINK` detection that aborts the write, the privileged copy no longer follows an
attacker-planted symbolic link, closing the link-following EoP.

### Patch Completeness Assessment

The symbolic-link guard is **unconditional** (not behind a CFR feature flag), so it is
active on patched builds without requiring a flag to be enabled. Apply KB5120240
(23H2) / KB5121003 (24H2) or later.

---

## Detection Guidance

**Behavioural.** Creation of registry **symbolic links** (`REG_LINK` keys) at
Assistive-Technology settings locations by non-administrative processes, followed by
ATBroker activity; unexpected AT-settings writes landing in privileged hives on
unpatched builds. Audit registry symbolic-link creation where feasible.

**Config.** No feature flag — the fix ships active in the patched binary.

---

## References

- MSRC advisory — CVE-2026-61358 (Windows Accessibility Infrastructure (ATBroker.exe) Elevation of Privilege), released 2026-08-11, KB5121003 (24H2) / KB5120240 (23H2).
- Full binary diff: `/data/patch_diffs/atbroker_exe-cve-2026-61358-ghidriff.md`
