Sceawere

Vulnerability Detail

CVE-2026-65680UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Microsoft OneDrive Link Following Privilege Escalation

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.7
Creation Date
6h ago
Vendor
Microsoft
Product
OneDrive for MacOS
Attack Type
CWE-59: Improper Link Resolution Before File Access ('Link Following')
Vector String
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.7",
  "pubDate": "2026-08-11T18:18:08.277Z",
  "pubdate": "2026-08-11T18:18:08.277Z",
  "executiveSummary": "An improper link resolution before file access vulnerability, commonly referred to as link following, exists in Microsoft OneDrive. This security flaw enables a locally authenticated attacker to manipulate file system operations and elevate their privileges on the target system.\nThe vulnerability resides within the file access and resolution mechanisms of Microsoft OneDrive. When the application processes file interactions without adequately validating symbolic links, junctions, or hard links, it creates a window for race conditions or unintended file context manipulation.\nThe primary impact of this vulnerability is local privilege escalation, potentially allowing an attacker to interact with or modify files outside their intended permission boundary, leading to system compromise or unauthorized administrative access.\nExploitation of this vulnerability requires local access to the affected system and an authenticated user context. The attacker must possess the capability to create and manipulate file system links in locations processed by the OneDrive application.\nRisk implications are significant for multi-user environments or systems where standard users share access with service accounts, as successful exploitation bridges privilege tiers and compromises host integrity.",
  "technicalDetails": "The root cause of the vulnerability stems from improper link resolution before file access, categorized under CWE-59. The affected component in Microsoft OneDrive fails to perform secure atomic checks or properly resolve symbolic links and directory junctions prior to executing read, write, or traversal operations against target file paths.\nThe vulnerability is exposed locally and does not require network exposure or remote interaction. Authentication requirements are minimal, necessitating only a standard, unprivileged local user account capable of executing local code or manipulating the local file system.\nThe exploitation method relies on Time-of-Check to Time-of-Use (TOCTOU) race conditions or predictable file handling where the OneDrive application follows a user-controlled link to an unintended system file. An attacker establishes a symbolic link or junction pointing from a monitored or manipulated location within the OneDrive synchronization directory or application working path to a sensitive system file or directory.\nThe step-by-step attack flow proceeds as follows: First, the attacker identifies a file operation performed by Microsoft OneDrive that lacks proper link verification. Second, the attacker prepares a malicious link structure, substituting a standard file or directory path with a symbolic link pointing to a restricted system resource. Third, the attacker triggers the file access condition within OneDrive, causing the application to process the linked target under the application's elevated security context. Finally, the improper link resolution results in unauthorized file access, modification, or leakage of sensitive data, culminating in local privilege escalation."
}
CVE-2026-65680: Microsoft OneDrive Link Following Privilege Escalation (MEDIUM Severity, CVSS: 6.7) - Sceawere