vciy

Microsoft windows, link following: 24 records, one defect family

Microsoft windows has been reported 24 separate times for the same kind of mistake, CWE-59, between 2019-06-12 and 2026-08-11. A defect family is our own grouping of the CVE corpus: every record naming one product and one weakness class, collected so a repeat is visible as a repeat. No public source publishes this, and what this page counts is how often this one product has gone wrong in this one way.

What this page is, and what it is not

The records are public. This grouping is not, and this one took more than a lookup. Every record here carries CWE-59, which matches exactly. The product name does not: the authorities wrote it 4 different ways, and no text match joins those strings, so a search for any one spelling finds a fraction of what exists and gives no sign the rest is there. Our own embedding, pro@dim2000, read those 4 groups, of 11, 6, 4, 3 records, and found they name one product. That is how 24 records no public source connects came to be on one page, and it is the part you cannot look up. Every spelling stays printed beside its own records, because a judgement you cannot inspect is a judgement you should not cite, and if one of them is a different product this family is wrong and its count is wrong with it.

One record is an incident. 24 filings, between 2019-06-12 and 2026-08-11, all landing on the same weakness class in the same product, is a habit in what gets reported here, and a habit is something you can plan around. This is what we held on 2026-09-20.

A repeat is evidence about where to look. If you are reviewing Microsoft windows, the records below say which mistake has already been found more than once, which is the cheapest place a reviewer can start. If you are asking the vendor a question, a count under one weakness class is a better question than any single record is.

What this page cannot tell you is decided by what was joined. A product name and a weakness class settled membership, so those two values are the whole of what the page asserts. Records here may sit in the same line of code or in unrelated parts of the product, and we hold no value that separates those cases. A fixed version named in one record closes that record and says nothing about the others. And nothing here describes anyone's systems, because no value in this family connects a product name to an installation.

CVE-2024-30076CVE-2024-43551CVE-2025-48799CVE-2025-59510CVE-2026-25187CVE-2026-32212CVE-2026-42989CVE-2026-45586CVE-2026-49176CVE-2026-49180CVE-2026-49791CVE-2020-0616CVE-2020-0638CVE-2020-0683CVE-2020-0730CVE-2020-0779CVE-2020-0787CVE-2019-0986CVE-2019-1053CVE-2019-1064CVE-2019-1069CVE-2024-26238CVE-2026-50364CVE-2026-62832
This family arrived in 4 groups between 2019-06-12 and 2026-08-11. The largest holds 11 of the 24 records and the next holds 6, so no single announcement accounts for most of it.

The names the authorities used

4 different ways, each written by whoever filed the records under it. They are printed as written rather than tidied, because the tidying is the step that would hide what was merged.

microsoft windows
microsoft windows 10 version 1607
microsoft windows 10 version 1703
microsoft windows 10 version 21h2

These records name more than one weakness class each. All 14 carry CWE-59, which is what this family was grouped on, and 2 of them also name CWE-269, improper privilege management. The roster below shows what each record names; both readings are the record's own, filed together by the same authority.

Family membership: computed, pro@dim2000

What pulled them together

These records reached one family from 4 separate groups. A join on the product name alone could not see they were the same, because the authorities wrote the product and its versions differently each time. The grouping was computed by pro@dim2000.

11 recordsCVE-2024-30076, CVE-2024-43551, CVE-2025-48799, CVE-2025-59510, CVE-2026-25187, CVE-2026-32212, CVE-2026-42989, CVE-2026-45586, CVE-2026-49176…
6 recordsCVE-2020-0616, CVE-2020-0638, CVE-2020-0683, CVE-2020-0730, CVE-2020-0779, CVE-2020-0787
4 recordsCVE-2019-0986, CVE-2019-1053, CVE-2019-1064, CVE-2019-1069
3 recordsCVE-2024-26238, CVE-2026-50364, CVE-2026-62832

What the records offer

14 of 24 records publish a fixed version. For the other 10, held sources name none.

5 records are listed by CISA with a required action, which carries a federal remediation deadline on its own page.

The earliest was published 2019-06-12 and the latest 2026-08-11. That span is how long this product kept producing this weakness, not how long any one record took to fix.

What this family was researched, not held

Windows services keep following a link an ordinary user can redirect

Every record here has the same shape: a privileged Windows component performs a file operation on a path that an unprivileged user can redirect with a junction or a symbolic link. The pattern was public early. In June 2019 Microsoft shipped updates for four privilege escalation flaws that a researcher using the name SandboxEscaper had published the previous month, among them CVE-2019-1069 in Task Scheduler and CVE-2019-1064 in the AppX Deployment Service, which CISA describes as improper handling of hard links. In March 2020 the researcher itm4n published the Background Intelligent Transfer Service case, CVE-2020-0787, where an undocumented remote procedure call moved a file as SYSTEM and mountpoints, oplocks and symbolic links redirected it, and called it yet another example of privileged file operation abuse in Windows 10. Microsoft's own record wording now names the class outright: CVE-2025-48799 in the Windows Update Service and CVE-2026-62832 in the Windows User Profile Service both read improper link resolution before file access, link following, six and seven years after the 2019 batch.

These are local elevation records, useful to someone who already runs code as a user on the machine. Unprivileged accounts can create links and junctions, so every privileged file operation is a candidate and the vendor fixes them one component at a time. Read each record for the component and build it names, because the group shows a habit, not a single missing patch.

2019-06-12Microsoft shipped fixes for four privilege escalation flaws SandboxEscaper had published the previous month, including CVE-2019-1069 and…
2020-03-11itm4n published the analysis of CVE-2020-0787, a file move performed as SYSTEM and redirected with mountpoints, oplocks and symbolic links.
2022-01-28CISA added CVE-2020-0787 to the Known Exploited Vulnerabilities catalog, saying an actor can use it to run code with system level privileges.
2022-03-15CISA added CVE-2019-1064 and CVE-2019-1069 to the catalog, both marked as used in known ransomware campaigns.
2025-07-08Microsoft published CVE-2025-48799, link following in the Windows Update Service, classed as CWE-59.
2026-08-11Microsoft published CVE-2026-62832, link following in the Windows User Profile Service, classed as CWE-59.

This note shows the records describe the same kind of mistake. It does not say they are one vulnerability, that they affect the same systems, or that patching one of them addresses any other.

Written from securityweek.com, itm4n.github.io, cisa.gov, cve.org, cve.org. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

What this page does not cover

This is a family of records that read alike. It is not a shared vulnerability, not an inventory, and not a statement that one fix closes the rest. Each record's own state, its own dates and its own receipts are on its own page.

Grouped by shared product and weakness, not by shared vulnerability. Each record's own state is on its own page.

Everything this vendor has, including records outside this family:

CVE-2019-0986Windows User Profile Service Elevation of Privilege Vulnerability
CVE-2019-1053Windows Shell Elevation of Privilege Vulnerability
CVE-2019-1064Windows Elevation of Privilege Vulnerability
CVE-2019-1069Task Scheduler Elevation of Privilege Vulnerability
CVE-2020-0616no title heldDenial of Service
CVE-2020-0638no title heldElevation of Privilege
CVE-2020-0683no title heldElevation of Privilege
CVE-2020-0730no title heldElevation of Privilege
CVE-2020-0779no title heldElevation of Privilege
CVE-2020-0787no title heldElevation of Privilege
CVE-2024-26238Microsoft PLUGScheduler Scheduled Task Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2024-30076Windows Container Manager Service Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2024-43551Windows Storage Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2025-48799Windows Update Service Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2025-59510Windows Routing and Remote Access Service (RRAS) Denial of Service VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-25187Winlogon Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-32212Universal Plug and Play (upnp.dll) Information Disclosure VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-42989Winlogon Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-45586Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-49176Windows WalletService Elevation of Privilege VulnerabilityCWE-269: Improper Privilege Management
CVE-2026-49180Universal Plug and Play (upnp.dll) Information Disclosure VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-49791Windows Routing and Remote Access Service (RRAS) Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-50364Windows Backup Service Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…
CVE-2026-62832Windows User Profile Service Elevation of Privilege VulnerabilityCWE-59: Improper Link Resolution Before File…

24 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.