CVE-2026-33694

This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privileges. As a result, this condition potentially facilitates arbitrary code execution, whereby an attacker may exploit the vulnerability to execute malicious code with elevated SYSTEM privileges.
CVSS

No CVSS.

Configurations

No configuration.

History

23 Apr 2026, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-23 19:17

Updated : 2026-04-24 14:50


NVD link : CVE-2026-33694

Mitre link : CVE-2026-33694

CVE.ORG link : CVE-2026-33694


JSON object : View

Products Affected

No product.

CWE
CWE-59

Improper Link Resolution Before File Access ('Link Following')