Severity: High
A high-severity vulnerability has been disclosed affecting the Windows Update Stack, impacting Windows 11 and Windows Server environments.
The vulnerability, tracked as CVE-2026-81963, is caused by improper link resolution before file access, commonly referred to as a link-following vulnerability. flaw in the way the Windows Update Stack resolves file or directory links during its update operations means that a locally authenticated, low-privileged attacker can craft a symbolic link or junction point that causes the update process to access or manipulate a file or directory it would not ordinarily have permission to reach.
By exploiting this behaviour, an attacker with local access can leverage the elevated privileges of the update stack to overwrite or tamper with sensitive files, potentially achieving full privilege escalation on the affected host. This type of vulnerability is commonly used as a second-stage exploit within broader attack chains, where an attacker already has limited access to a system and seeks to escalate to SYSTEM or administrator-level privileges.
As part of Beeks’ commitment to supporting operational resilience and cyber risk management, this advisory is intended to help organisations assess exposure and implement appropriate mitigations.
Affected software:
- Windows Update Stack – affected Windows releases prior to the patched version
- Windows 11 23H2 – 26H1
- Windows Server 2025
Immediate Actions Required:
- Apply the latest security patches released by Microsoft to remediate this vulnerability — this is the primary and most effective remediation.
- Where immediate patching is not possible, restrict local interactive access to affected systems to minimise the risk of exploitation by low-privileged users.
- Review and audit systems for indicators of unexpected privilege escalation events, particularly on hosts exposed to lower-privileged or untrusted user accounts.
Further Information:
For detailed information on the vulnerability, please refer to the following sources:
https://nvd.nist.gov/vuln/detail/CVE-2026-81963
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-81963
If you have any questions or require further assistance, please contact [email protected] or reach out to your Beeks account representative.
This advisory is issued to help ensure the security of your systems and prevent unauthorised access to sensitive data. Beeks remains committed to providing timely security information and support to safeguard your infrastructure.
Beeks will continue to monitor this and related vulnerabilities and provide updates through our Security Advisory Feed.






