Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Local Privilege Escalation Vulnerability (ZDI‑26‑606) in Windows Compatibility Appraiser Allows SYSTEM Code Execution

A newly disclosed Windows vulnerability (ZDI‑26‑606) lets a local attacker elevate from LOCAL SERVICE to SYSTEM by abusing a symbolic link in the Compatibility Appraiser scheduled task. The flaw underscores the need for robust patch‑management and privileged‑task monitoring in SOC 2 programs.

LiveThreat™ Intelligence · 📅 August 25, 2026· 📰 zerodayinitiative.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Local Privilege Escalation Vulnerability in Windows Compatibility Appraiser Enables SYSTEM Code Execution

What Happened — A new vulnerability (ZDI‑26‑606 / CVSS 7.0) was disclosed in the Microsoft Windows Compatibility Appraiser scheduled task. By creating a symbolic link, a local attacker who can run code as LOCAL SERVICE can cause the task to delete arbitrary files and ultimately execute code as SYSTEM. Microsoft has already released a security update that patches the flaw.

Why It Matters for Compliance & Audit Readiness

  • The issue is a classic example of a control gap that SOC 2’s CC6.1 – Patch Management and CC6.2 – Change Management controls are designed to detect and remediate.
  • Continuous evidence of timely patch deployment and privileged‑task monitoring is essential to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s Control Mapping capability can automatically map this vulnerability to the relevant SOC 2 controls and capture the update‑install logs as audit‑ready evidence.

Who Is Affected — Any organization running Microsoft Windows (desktop, server, or virtualized) across sectors such as technology, finance, healthcare, and government.

Recommended Actions

  • Deploy Microsoft’s security update immediately on all Windows endpoints.
  • Verify that the Compatibility Appraiser scheduled task now runs with the default permissions and that no symbolic‑link abuse is possible.
  • Add the task’s configuration to your change‑management inventory and enable continuous monitoring for any future modifications.
  • Document the patch‑deployment process and retain logs as part of your SOC 2 evidence package.

Technical Notes

  • Attack Vector: Local privilege escalation via symbolic‑link abuse of the Compatibility Appraiser scheduled task.
  • CVSS: 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
  • CVE: Not assigned; referenced as ZDI‑26‑606 / ZDI‑CAN‑28205.
  • Fix: Microsoft security update (see MSRC advisory).

Source: Zero Day Initiative Advisory – ZDI‑26‑606

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-606/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Answer one control objective. Answer ten frameworks.

The Verisq Common Framework is a spine of 84 control objectives that SOC 2, ISO 27001, NIST CSF, CMMC, HIPAA, PCI DSS, HITRUST, GDPR, ISO 42001 and NIST AI RMF map onto — each graded honestly. Satisfy an objective once and every framework that recognizes it lights up at its real strength.

See how the Verisq Common Framework works →