CVE-2026-72971

EUVD-2026-56603
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 27.52%
Affected Products (NVD)
VendorProductVersion
microsoftwindows_11_26h1
𝑥
< 10.0.28000.2704
𝑥
= Vulnerable software versions
Windows Releases
Platform
Version
Windows 11
26H1 (arm64, x64)