CVE-2026-70348ImportantRevised 12 Aug
Windows Management Services Denial of Service Vulnerability
Assessment
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
- Severity
- Important
- CVSS base score
- 5.5CVSS:3.1/
AV:L/ AC:L/ PR:L/ UI:N/ S:U/ C:N/ I:N/ A:H/ E:U/ RL:O/ RC:C - Impact
- Denial of Service
- EPSS, next 30 days
- 0.4%Higher than 36% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Windows Management Services
- Weakness
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 12 Aug 2026Updated an acknowledgement. This is an informational change only.
Updates that fix it
3 KBs| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5120994 | Security Hotpatch Update | Required | Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems and 1 more | All CVEs in KB5120994 |
| KB5121000 | Security Update | Required | Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems | All CVEs in KB5121000 |
| KB5121003 | Security Update | Required | Windows 11 Version 24H2 for ARM64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for ARM64-based Systems and 1 more | All CVEs in KB5121003 |
Affected products
Windows6 affected products
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows 11 Version 25H2 for ARM64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows 11 Version 26H1 for ARM64-based Systems
- Windows 11 version 26H1 for x64-based Systems