Important CVSS 7.8 EPSS 0.0368 🔬 Patch diffed 2026-08 archive

Executive Summary

Improper link resolution before file access ('link following') in Windows Accessibility Infrastructure (ATBroker.exe) allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.0368 — 0.88692 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.0368
probability of exploitation in the next 30 days
0.88692 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

14 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5120238 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Elevation of Privilege Yes

Patches

4 patches
Article Type Restart
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes

Patch Diff

ghidriff · atbroker.exe (KB5120240)

Link-following elevation of privilege (CWE-59) in the Windows Accessibility Infrastructure ATBroker.exe (Assistive Technology Broker), local EoP to SYSTEM (Important, AV:L, CVSS 7.8, Exploitation More Likely). ATBroker copies Assistive-Technology settings between registry locations via SettingsCopier::CopyATSettings / SetRegKeyValue (RegOpenKeyExW -> RegSetValueExW). PRE: the destination key was opened and written WITHOUT checking whether it was a registry symbolic link, so a low-privileged attacker who plants a REG_LINK at the AT-settings target could redirect ATBroker's privileged write to an attacker-chosen key (e.g. a sensitive HKLM location) - link following -> EoP to SYSTEM. Diff of ATBroker.exe 10.0.22621.6783 -> .7219 (Aug 11 2026, KB5120240, Win11 23H2; 24H2 ships the equivalent fix at 10.0.26100.9168 / KB5121003) confirms the fix: the patched CopyATSettings adds an unconditional symbolic-link guard before writing - it opens the key with REG_OPTION_OPEN_LINK (ulOptions=8), queries the special SymbolicLinkValue, and if the key is a registry symbolic link (REG_LINK, type 6) it aborts with a failure HRESULT (0x800705b8) instead of calling RegSetValueExW. The guard is not CFR-gated (ships active in the patched binary).

Pre-patch version 10.0.22621.6783 Download
Post-patch version 10.0.22621.7219 Download
Function Address Change Note
SettingsCopier::CopyATSettings code change code (adds registry symbolic-link check before privileged write) Post: opens the destination key with REG_OPTION_OPEN_LINK (8), queries SymbolicLinkValue; if the key is a REG_LINK (type 6) it aborts (0x800705b8) instead of writing. Pre: opened and wrote the key with no symlink check.
SettingsCopier::SetRegKeyValue code change code (write path folded into the guarded CopyATSettings flow) Pre: RegOpenKeyExW -> RegSetValueExW -> RegCloseKey with no link check. Post: the value write now occurs only after the CopyATSettings symbolic-link check passes.
View full diff report View RCA report

Attack Path

A planted registry symbolic link redirects ATBroker's privileged AT-settings write to an attacker-chosen key

Attack path for CVE-2026-61358 A planted registry symbolic link redirects ATBroker's privileged AT-settings write to an attacker-chosen key 01 — ENTRY Low-privileged attacker plants a registry symbolic link A REG_LINK key is created at the location ATBroker copies AT settings to. AV:L / PR:L / AC:L (local, low privilege). 02 — CONTROLLED INPUT Triggers the AT-settings copy in ATBroker SettingsCopier::CopyATSettings / SetRegKeyValue opens the destination key and writes AT-settings values from a privileged context. 03 — MISSING CHECK Privileged write follows the symbolic link (CWE-59) Pre-patch the key is opened and written without a symlink check, so the write is redirected through the REG_LINK to an attacker-chosen key. 04 — IMPACT Redirected privileged write -> SYSTEM The write lands in a sensitive location the attacker could not otherwise modify, yielding elevation of privilege to SYSTEM.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules

Acknowledgments