Improper Link Resolution Before File Access ('Link Following') (CWE-59)
Windows File Server Resource Management Service Elevation of Privilege Vulnerability. This vulnerability is associated with CWE-59, which is "Improper Link Resolution Before File Access ('Link Following')". The vulnerability has a CVSS v3.1 base score of 7.3, indicating a high severity. It requires local access and low privileges, with user interaction needed for exploitation.
If exploited, this vulnerability could allow an attacker to elevate their privileges on the affected system. The CVSS score indicates high impact on confidentiality, integrity, and availability. This means an attacker could potentially access sensitive information, modify system files or data, and disrupt system operations. Given the nature of the File Server Resource Management Service, this could affect file storage and access management across the network.
There is no evidence that a public proof-of-concept exists. There is no evidence of proof of exploitation at the moment.
A patch is available for this vulnerability. Microsoft released the patch on April 9, 2024, as part of their regular security updates. The patch can be obtained through the Microsoft Update Guide.
1. Apply the security update provided by Microsoft as soon as possible. 2. Implement the principle of least privilege, ensuring users and processes only have the minimum necessary permissions. 3. Monitor and audit file server activities for any suspicious behavior. 4. Restrict local access to critical systems where possible. 5. Educate users about the risks of interacting with untrusted files or links, as user interaction is required for exploitation. 6. Consider implementing additional access controls and monitoring on the File Server Resource Management Service. 7. Regularly update and patch Windows systems to protect against this and other vulnerabilities.
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Detection for the vulnerability has been added to Qualys (92128)
A CVSS base score of 7.3 has been assigned.
Feedly found the first article mentioning CVE-2024-26216. See article
Feedly estimated the CVSS score as MEDIUM
NVD published the first details for CVE-2024-26216
EPSS Score was set to: 0% (Percentile: 8%)
EPSS Score was set to: 0.04% (Percentile: 7.9%)