Vulnerability Details CVE-2026-72971
Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.sys) allows an authorized attacker to perform tampering locally.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 28.8%
CVSS Severity
CVSS v3 Score 5.5
Products affected by CVE-2026-72971
-
cpe:2.3:o:microsoft:windows_11_26h1:-
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.1575
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.1719
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.1836
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.2113
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.2269
-
cpe:2.3:o:microsoft:windows_11_26h1:10.0.28000.2525