CVE-2026-70348HighCVSS 5.5
Windows Management Services Denial of Service Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attacker to deny service locally.
🎯 Affected products6
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows 11 Version 25H2 for ARM64-based Systems
- Windows 11 Version 25H2 for x64-based Systems
- Windows 11 Version 26H1 for ARM64-based Systems
- Windows 11 version 26H1 for x64-based Systems
✅ Remediation
KB5121003 (Security Update) — fixed build 10.0.26200.9168 KB5120994 (Security Hotpatch Update) — fixed build 10.0.26200.9106 KB5121003 (Security Update) — fixed build 10.0.26100.9168 KB5120994 (Security Hotpatch Update) — fixed build 10.0.26100.9106 KB5121000 (Security Update) — fixed build 10.0.28000.2704
🔗 References (7)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70348
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121003
- referencehttps://support.microsoft.com/help/5121003
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5120994
- referencehttps://support.microsoft.com/help/5120994
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5121000
- referencehttps://support.microsoft.com/help/5121000