CVE-2026-72971
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Description
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
In plain language
AI Act nowOn Windows 11, a Windows filesystem driver (unionfs.sys) has a link-handling weakness that can let an attacker tamper with files if they can run authorized code on the device—this is serious enough to patch urgently.
In Windows Container Isolation FS Filter Driver (unionfs.sys), improper link resolution before file access (“link following”) can let an authenticated/authorized local attacker tamper with files on Windows 11; fixed in Windows 11 10.0.28000.2704.
What to do now
- Check your Windows 11 build/version (press Win+R, type "winver", press Enter) and confirm whether you are on a version earlier than 10.0.28000.2704.
- Install Microsoft’s update for CVE-2026-72971 from the Microsoft Update Guide and ensure it brings your Windows 11 build to 10.0.28000.2704.
- If you can’t update immediately, restrict who can log on to the affected machines and reduce the chance of an “authorized local attacker” scenario (tighten admin access, remove unnecessary accounts, and follow least-privilege).
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:HIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
- Microsoft выпустила патчи более чем для 400 уязвимостейru-ru·Хакер (xakep.ru)· Exploited Windows Lazarus
- Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)en-us·Help Net Security· Exploited Windows Lazarus Group
- ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Accessen·The Hacker News· PoC Microsoft Defender privilege-escalation
- Microsoft Patch Tuesday, August 2026 Security Update Reviewen-us·Qualys Security Blog· Exploited Windows patch-tuesday
- Microsoft Plugs Nearly 400 Security Holesen-us·Krebs on Security· Exploited Windows patch-tuesday
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Dayen-us·SecurityWeek· Exploited Windows Lazarus group
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-daysen-us·BleepingComputer· Exploited Windows Lazarus group
- Microsoft Patch Tuesday August 2026 - SANS ISCen·SANS Internet Storm Center· Exploited Windows zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-72971 and every CVE in our database. Create a free account — no credit card required.
Create Free Account