CVE-2026-70019
Windows hard link in Windows Compressed Folder allows an unauthorized attacker to disclose information over a network.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
- EPSS probability
- 1.06%
- CWE
- CWE-65
- Published
- 2026-09-08
- Last modified
- 2026-09-10
Affected products
- Microsoft Windows 11 version 23H2
- Microsoft Windows 11 Version 23H2
- Microsoft Windows 11 Version 24H2
- Microsoft Windows 11 Version 25H2
- Microsoft Windows 11 version 26H1
- Microsoft Windows Server 2025
- Microsoft Windows Server 2025 (Server Core installation)
Weakness type
Related vulnerabilities
- CVE-2022-23742 — Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for...
- CVE-2020-6013 — ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who...
- CVE-2019-19231 — An insecure file access vulnerability exists in CA Client Automation 14.0, 14.1, 14.2, and 14.3...
- CVE-2019-8454 — A local attacker can create a hard-link between a file to which the Check Point Endpoint Security...
- CVE-2019-8452 — A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point...
- CVE-2019-8455 — A hard-link created from the log file of Check Point ZoneAlarm up to 15.4.062 to any file on the...