Local Privilege Escalation Vulnerability in Windows Compatibility Appraiser Enables SYSTEM Code Execution
What Happened — A new vulnerability (ZDI‑26‑606 / CVSS 7.0) was disclosed in the Microsoft Windows Compatibility Appraiser scheduled task. By creating a symbolic link, a local attacker who can run code as LOCAL SERVICE can cause the task to delete arbitrary files and ultimately execute code as SYSTEM. Microsoft has already released a security update that patches the flaw.
Why It Matters for Compliance & Audit Readiness
- The issue is a classic example of a control gap that SOC 2’s CC6.1 – Patch Management and CC6.2 – Change Management controls are designed to detect and remediate.
- Continuous evidence of timely patch deployment and privileged‑task monitoring is essential to demonstrate due diligence during a SOC 2 audit.
- Verisq’s Control Mapping capability can automatically map this vulnerability to the relevant SOC 2 controls and capture the update‑install logs as audit‑ready evidence.
Who Is Affected — Any organization running Microsoft Windows (desktop, server, or virtualized) across sectors such as technology, finance, healthcare, and government.
Recommended Actions
- Deploy Microsoft’s security update immediately on all Windows endpoints.
- Verify that the Compatibility Appraiser scheduled task now runs with the default permissions and that no symbolic‑link abuse is possible.
- Add the task’s configuration to your change‑management inventory and enable continuous monitoring for any future modifications.
- Document the patch‑deployment process and retain logs as part of your SOC 2 evidence package.
Technical Notes
- Attack Vector: Local privilege escalation via symbolic‑link abuse of the
Compatibility Appraiserscheduled task. - CVSS: 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
- CVE: Not assigned; referenced as ZDI‑26‑606 / ZDI‑CAN‑28205.
- Fix: Microsoft security update (see MSRC advisory).