important · Privilege — Windows Update
Attackers are exploiting Windows Update Stack link following to turn a standard local foothold into SYSTEM.
Affects
Microsoft Windows 11 and Windows Server 2025, desktop and server operating systems.
Low-privilege code on an affected Windows 11 or Windows Server 2025 host can arrange a link condition that redirects the updater’s privileged file access and yields SYSTEM.
Detail and 5 sources
Microsoft’s CNA record establishes the affected and fixed builds, and exploitation is reported in the wild. We do not know the state of pre-fix image acceptance, revocation or end-of-life hardware coverage.
Sources
Research2026 年 9 月のセキュリティ更新プログラム (月例)ResearchCVE-2026-81963 - Vulnerability Details - OpenCVEResearchZero Day Initiative — The September 2026 Security Update ReviewResearch微軟修補Windows更新元件與ALPC的零時差漏洞,並指出已被用於實際攻擊 | iThomeVendorแจ้งเตือนช่องโหว่ความปลอดภัยระดับสูงในการยกระดับสิทธิ์ (Privilege Escalation) บน Microsoft Windows (CVE-2026-81963) | การแจ้งเตือนภัยคุกคาม | ศูนย์รักษาความมั่นคงปลอดภัยไซเบอร์ มหาวิทยาลัยพะเยา