CVE-2026-45586
Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
Description
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
In plain language
AI Act nowCVE-2026-45586 is a serious local Windows security flaw that can let an attacker gain higher privileges on a machine, and a typical small business should act quickly—especially on affected Windows versions.
What to do
- Update all affected Microsoft Windows systems to the latest security fixes for CVE-2026-45586 (ask your IT person to confirm the exact patch level). 2) If you can’t patch immediately, isolate vulnerable machines (especially servers) from remote access and restrict access to reduce the chance of a local foothold. 3) Check whether any accounts with normal user access were recently used for suspicious activities, and prioritize reviewing logs around the time window your IT person believes attackers may have tried access.
CVSS Vector Breakdown
Exploitability
AV:LAttack VectorLocal
AC:LAttack ComplexityLow
PR:LPrivileges RequiredLow
UI:NUser InteractionNone
Scope
S:UScopeUnchanged
Impact
C:HConfidentialityHigh
I:HIntegrityHigh
A:HAvailabilityHigh
Weaknesses
Affected Products
Microsoft Corp
commercial·USaka Microsoft, microsoft corporation
and 45 more affected products View all →
Exploitability
Official Patch Available
Attack Graph
Products CVE Techniques Tactics
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniques Collection
Discovery
References
News mentions
21- Опубликован эксплоит для 0-day-уязвимости LegacyHive в Windowsru-ru·Хакер (xakep.ru)· PoC Windows User Profile Service (ProfSvc) privilege-escalation
- Microsoft исправила уязвимость RoguePlanet. Исследователь утверждает, что патч опасенru-ru·Хакер (xakep.ru)· Patch Microsoft Defender privilege-escalation
- В Microsoft работают над патчем для 0-day-уязвимости RoguePlanetru-ru·Хакер (xakep.ru)· PoC Microsoft Defender Nightmare Eclipse
- Security Week 2625: непростой набор патчей от Microsoftru·Хабр — Информационная безопасность· PoC Windows Nightmare Eclipse (Chaotic Eclipse)
- Эксплоит GreatXML позволяет обойти шифрование BitLockerru-ru·Хакер (xakep.ru)· PoC Windows Nightmare Eclipse (Chaotic Eclipse)
- ИБ-исследователь Nightmare Eclipse раскрыл 0-day-уязвимость в Microsoft Defenderru-ru·Хакер (xakep.ru)· PoC Microsoft Defender Nightmare Eclipse (aka Chaotic Eclipse, MSNightmare)
- Microsoft исправила более 200 уязвимостей и шесть 0-day в своих продуктахru-ru·Хакер (xakep.ru)· Exploited Exchange Server rce
- New Windows Zero-Day Exploit ‘RoguePlanet’ Releaseden-us·SecurityWeek· PoC Windows Nightmare Eclipse
- Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-daysen-us·BleepingComputer· Patch Windows Nightmare Eclipse
- Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugsen·The Hacker News· Patch Windows patch-tuesday
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-45586 and every CVE in our database. Create a free account — no credit card required.
Create Free AccountPlain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows
