CVE-2026-72971ImportantDisclosed
Windows Container Isolation FS Filter Driver (unionfs.sys) Tampering Vulnerability
Assessment
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
- Severity
- Important
- CVSS base score
- 5.5CVSS:3.1/
AV:L/ AC:L/ PR:L/ UI:N/ S:U/ C:N/ I:H/ A:N/ E:U/ RL:O/ RC:C - Impact
- Tampering
- EPSS, next 30 days
- 0.4%Higher than 27.6% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Unlikely
- Publicly disclosed
- Yes
- Customer action
- Required: apply the update
- Component
- Windows Container Isolation FS Filter Driver (unionfs.sys)
- Weakness
- CWE-59: Improper Link Resolution Before File Access ('Link Following')
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 11 Aug 2026
Updates that fix it
1 KB| KB | Type | Restart | Applies to | Other CVEs |
|---|---|---|---|---|
| KB5121000 | Security Update | Required | Windows 11 Version 26H1 for ARM64-based Systems, Windows 11 version 26H1 for x64-based Systems | All CVEs in KB5121000 |
Affected products
Windows2 affected products
- Windows 11 Version 26H1 for ARM64-based Systems
- Windows 11 version 26H1 for x64-based Systems