← Back to Feed CACHED · 2026-07-30 03:57:43 · CACHE_KEY CVE-2026-50469
CVE-2026-50469 · CWE-59 · Disclosed 2026-07-14

Improper link resolution before file access

ASSESSED — NOISGATE V0.5
Vendor
Reassessed
Verdict:
Do you agree?
01 · The Real Story

Like leaving a spare key under the mat, except the mat only exists in houses that asked for it

CVE-2026-50469 is a CWE-59 (symlink / link-following) elevation-of-privilege flaw in the Windows Projected File System (prjflt.sys minifilter driver). A local, low-privileged attacker can craft NTFS junctions or symbolic links that redirect privileged file operations performed by the ProjFS driver into attacker-controlled locations, ultimately escalating to SYSTEM. Affected platforms span Windows 10 21H2/22H2, Windows 11 24H2/25H2/26H1, Windows Server 2019 and Server 2025. The fix shipped in the July 2026 Patch Tuesday cumulative updates (e.g. KB5101649 for Windows 11 26H1).

Microsoft rated this Important / 7.8, which is the standard CVSS bucket for a local low-priv-to-SYSTEM EoP. That score is technically accurate if ProjFS is running — but it overstates the real-world risk because ProjFS is an *optional Windows component* that ships disabled by default. It must be explicitly enabled via Enable-WindowsOptionalFeature -FeatureName Client-ProjFS. Outside of VFS for Git, Scalar monorepo tooling, and a handful of niche cloud-sync providers, most enterprise endpoints never turn it on. The vendor score prices in zero friction for feature adoption, and that is where it misleads defenders.

"Optional-feature symlink EoP in ProjFS: most fleets aren't even exposed."
02 · The Attack Path

5 steps from start to impact.

STEP 01

Attain local code execution

The attacker must already be running code as a standard (low-privilege) user on the target host. This could be via phishing payload, compromised RDP session, malware dropper, or lateral movement from another compromised host. The CVSS vector explicitly requires AV:L / PR:L — no remote attack path exists.
Conditions required:
  • Local code execution as a standard user on the target
Where this breaks in practice:
  • Requires a prior compromise stage; the vuln is not the entry vector
  • EDR / email-gateway / web-proxy should intercept common delivery mechanisms
Detection/coverage: Standard EDR telemetry (process creation, LOLBin use) detects the initial foothold stage.
STEP 02

Confirm ProjFS is enabled

The attacker checks whether the Client-ProjFS optional feature is active and whether prjflt.sys is loaded as a minifilter at altitude 189800. If ProjFS is not enabled, the entire chain is dead. The attacker can query fltmc instances or Get-WindowsOptionalFeature -Online -FeatureName Client-ProjFS (the latter needs elevation, but the former does not).
Conditions required:
  • ProjFS optional feature must be enabled on the host
Where this breaks in practice:
  • ProjFS ships disabled by default on all Windows SKUs
  • Only hosts running VFS for Git, Scalar, or custom ProjFS providers will have it
  • Estimated <5% of enterprise Windows endpoints have this feature enabled
Detection/coverage: No standard detection for feature enumeration; this is benign recon.
STEP 03

Create malicious symlinks / junctions

The attacker creates NTFS junctions or object-manager symlinks in a user-writable directory that is within or adjacent to a ProjFS virtualization root. These links redirect file operations that prjflt.sys performs at SYSTEM context to attacker-controlled target paths — for example, redirecting a projected placeholder write to overwrite a privileged binary or DLL.
Conditions required:
  • A ProjFS virtualization root the attacker can reach from their user context
  • Ability to create NTFS junctions (default for standard users on NTFS)
Where this breaks in practice:
  • Requires knowledge of the specific ProjFS provider layout on the target
  • Windows Defender / AMSI may flag known symlink-abuse tooling (e.g. CreateSymlink.exe from symboliclink-testing-tools)
Detection/coverage: Sysmon Event ID 11 (FileCreate) with ReparsePoint can catch junction creation in monitored directories. Microsoft Defender for Endpoint raises alerts on known symlink-abuse binaries.
STEP 04

Trigger privileged file operation via ProjFS callback

The attacker triggers a file access that causes prjflt.sys to invoke a provider callback (GetFileDataCallback or PRJ_NOTIFICATION_*) in a way that follows the crafted symlink under SYSTEM context. Because the driver does not properly validate the resolved link target (CWE-59), the operation writes to or reads from the attacker-redirected path with SYSTEM privileges.
Conditions required:
  • Successful symlink redirection not caught by path validation
Where this breaks in practice:
  • Exact trigger depends on the provider's callback behavior — the attacker may need to understand the provider's virtualization logic
  • No public PoC or exploit tool is available as of July 2026
Detection/coverage: Kernel audit events (Object Access → File) can capture anomalous SYSTEM-context writes to unexpected paths. Advanced EDR with minifilter stack monitoring may detect the mismatch.
STEP 05

Achieve SYSTEM-level code execution

The redirected privileged write allows the attacker to overwrite a system binary, plant a DLL for DLL-sideloading by a SYSTEM service, or write directly into a privileged configuration path. The attacker gains NT AUTHORITY\SYSTEM on the host, enabling credential dumping, persistence, or lateral movement.
Conditions required:
  • Successful exploitation of the ProjFS link-following flaw
Where this breaks in practice:
  • Credential Guard, PPL, and VBS mitigate some post-SYSTEM actions
  • If the host is hardened with application control (WDAC / AppLocker), planting new binaries is blocked
Detection/coverage: Endpoint detection: unexpected SYSTEM process trees, DLL loads from writable directories, and credential access (LSASS) attempts.
03 · Intelligence Metadata

The supporting signals.

In-the-Wild ExploitationNone observed. Not listed in CISA KEV. No GreyNoise or Shadowserver traffic associated. No vendor acknowledgment of active exploitation.
Proof-of-ConceptNone public. No GitHub repos, no researcher write-ups, no exploit-db entries as of 2026-07-30. CWE-59 symlink EoP patterns are well-understood (see ZDI's 2024 symlink series), but no weaponized PoC for this specific CVE.
EPSS Score0.00271 (0.27%) — bottom quartile. FIRST model predicts very low probability of exploitation in the next 30 days.
KEV StatusNot listed. No CISA KEV entry as of 2026-07-30.
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H — Local access, low complexity, low privileges, no user interaction. Scope unchanged (impact stays on the vulnerable host). Full CIA impact. Temporal score: 6.8.
Affected VersionsWindows 10 21H2 & 22H2 (x64, ARM64); Windows 11 24H2, 25H2, 26H1 (x64, ARM64); Windows Server 2019 (incl. Server Core); Windows Server 2025 (incl. Server Core). Only vulnerable when Client-ProjFS feature is enabled.
Fixed VersionsJuly 2026 Patch Tuesday cumulative updates: KB5101649 (Win 11 26H1), plus corresponding KBs for each affected OS version. No standalone ProjFS-only patch.
Scanning / ExposureNo Shodan/Censys/FOFA exposure — this is a local EoP, not remotely reachable. Endpoint vulnerability scanners (Tenable plugin 326859, Qualys QID pending) detect missing July 2026 CU. The real exposure question is how many hosts have ProjFS enabled — estimated <5% in a typical enterprise.
Disclosure Date2026-07-14 (July 2026 Patch Tuesday coordinated disclosure)
Reporting ResearcherNot publicly attributed by Microsoft in the advisory.
04 · The Call

noisgate verdict.

Final Verdict
DOWNGRADED to MEDIUM (5.0/10)

ProjFS is an optional Windows component that ships disabled by default and must be explicitly enabled — this single prerequisite eliminates exposure on the vast majority (~95%+) of enterprise Windows endpoints. The decisive factor for the downgrade is this narrow exposure population: only hosts running VFS for Git, Scalar, or custom ProjFS providers are reachable.

HIGH ProjFS is optional and disabled by default — confirmed via Microsoft documentation
HIGH No public PoC or in-the-wild exploitation exists
MEDIUM Exact affected-host population in a given enterprise (depends on dev tooling adoption)

Why this verdict

  • Optional-feature gate eliminates most of the fleet. ProjFS (Client-ProjFS) ships disabled by default on every Windows SKU. Only hosts that have explicitly enabled it — primarily developer workstations running VFS for Git or Scalar — are exposed. In a 10,000-host fleet, this is likely 200–500 machines at most.
  • Local access is a hard prerequisite. CVSS AV:L means the attacker must already have code execution on the target. This is a post-initial-access privilege escalation primitive, not an entry vector. The chain assumes a prior compromise stage.
  • No PoC, no ITW, bottom-quartile EPSS. There is no public exploit code, no campaign activity, no KEV listing, and EPSS sits at 0.27%. Near-term weaponization risk is low.
  • Role multiplier: ProjFS is overwhelmingly deployed on *developer workstations* (low-to-medium value). Build servers running VFS for Git could represent a supply-chain-relevant high-value role, but (a) Scalar has largely replaced VFS for Git in new deployments, (b) most CI/CD uses standard git clone without ProjFS, and (c) the population of ProjFS-enabled build servers is well below 1% of all ProjFS installs. The high-value-role floor does NOT trigger because the affected component is not canonically a high-value-role component and high-value deployments are far below the 1% threshold.

Why not higher?

To reach HIGH, the vulnerability would need either a broader exposed population, active exploitation, or a canonical high-value deployment role. ProjFS fails all three tests: it is an opt-in feature on <5% of endpoints, has no exploitation activity, and its primary habitat is developer workstations — not domain controllers, identity providers, hypervisors, or network edge devices. The build-server supply-chain scenario is theoretically possible but practically negligible (<1% of ProjFS installs).

Why not lower?

When ProjFS *is* enabled, the chain is straightforward — low complexity, no user interaction, standard-user to SYSTEM. CWE-59 symlink EoP is a well-researched class with known tooling patterns, and ProjFS has seen a steady cadence of EoP CVEs throughout 2025–2026, suggesting ongoing researcher attention. A LOW rating would understate the impact on the subset of hosts that are actually exposed.

05 · Compensating Control

What to do — in priority order.

  1. Disable ProjFS on hosts that don't need it — Run Disable-WindowsOptionalFeature -Online -FeatureName Client-ProjFS on endpoints where VFS for Git / Scalar / custom providers are not in use. This completely eliminates the attack surface with zero operational cost. Audit enablement fleet-wide via SCCM/Intune configuration baselines. No mitigation SLA applies at MEDIUM — go straight to the 365-day remediation window.
  2. Inventory ProjFS-enabled hosts — Query Get-WindowsOptionalFeature -Online -FeatureName Client-ProjFS across your fleet via your endpoint management tool to identify the actual exposed population. Prioritize patching this subset within your 365-day remediation window.
  3. Harden developer workstations with WDAC or AppLocker — Application control policies prevent an attacker from dropping and executing arbitrary binaries even after achieving SYSTEM, blunting the post-exploitation impact of this and similar local EoP chains.
  4. Monitor for symlink/junction creation in ProjFS directories — Deploy Sysmon with FileCreate (Event ID 11) rules that alert on reparse-point creation in known ProjFS virtualization roots (typically under VFS for Git working directories). This provides detective coverage while awaiting the patch.
What doesn't work
  • Network segmentation / firewall rules — This is a local EoP, not a network attack. Firewall rules do not affect the attack path.
  • WAF / IDS / IPS — No network traffic is involved in exploitation. Network-layer detection is irrelevant.
  • Disabling SMB signing or NTLM hardening — Unrelated protocol-level controls; this vulnerability operates entirely within the local filesystem stack.
06 · Verification

Crowdsourced verification payload.

Run this script on each target Windows host with standard user privileges (no elevation needed for the feature query; elevation needed for hotfix check). Example: .\Check-CVE-2026-50469.ps1 in a PowerShell console. Deploy fleet-wide via Intune, SCCM, or your RMM.

noisgate-verify.ps1
POWERSHELLREAD-ONLYSAFE
#Requires -Version 5.1
<#
  Check-CVE-2026-50469.ps1
  Checks whether the host is vulnerable to CVE-2026-50469
  (ProjFS symlink EoP, July 2026 Patch Tuesday)
  Exit codes: 1 = VULNERABLE, 0 = PATCHED, 2 = UNKNOWN
#>

$ErrorActionPreference = 'Stop'

try {
    # Step 1: Check if ProjFS feature is enabled
    $projfs = Get-WindowsOptionalFeature -Online -FeatureName 'Client-ProjFS' 2>$null
    if (-not $projfs -or $projfs.State -ne 'Enabled') {
        Write-Output 'PATCHED - ProjFS feature is not enabled on this host. Not vulnerable.'
        exit 0
    }

    Write-Output '[!] ProjFS (Client-ProjFS) is ENABLED on this host.'

    # Step 2: Check for July 2026 cumulative update
    # Known KBs for the July 2026 Patch Tuesday fix:
    $patchKBs = @('KB5101649','KB5101638','KB5101632','KB5101625','KB5099539','KB5101636')
    $installedHotfixes = Get-HotFix 2>$null | Select-Object -ExpandProperty HotFixID

    $patched = $false
    foreach ($kb in $patchKBs) {
        if ($installedHotfixes -contains $kb) {
            Write-Output "PATCHED - July 2026 update $kb is installed."
            $patched = $true
            break
        }
    }

    if (-not $patched) {
        # Fallback: check prjflt.sys file version
        $driverPath = "$env:SystemRoot\System32\drivers\prjflt.sys"
        if (Test-Path $driverPath) {
            $ver = (Get-Item $driverPath).VersionInfo.FileVersion
            Write-Output "[i] prjflt.sys version: $ver"
        }
        Write-Output 'VULNERABLE - ProjFS is enabled and July 2026 cumulative update is NOT installed.'
        exit 1
    }
    exit 0
}
catch {
    Write-Output "UNKNOWN - Error during check: $_"
    exit 2
}
07 · Bottom Line

If you remember one thing.

TL;DR
CVE-2026-50469 is a local privilege escalation in Windows Projected File System that noisgate downgrades to MEDIUM (5.0) because ProjFS ships disabled by default and only a small slice of your fleet will have it enabled. Monday morning: run a fleet-wide query for Client-ProjFS enablement status via Intune or SCCM — this takes minutes and tells you exactly how many hosts are actually exposed. Disable ProjFS on any host that does not actively need it. For the remaining exposed hosts (likely developer workstations), schedule the July 2026 cumulative update within the noisgate remediation SLA of 365 days. There is no noisgate mitigation SLA at MEDIUM — go straight to the remediation window. If your exposed population includes CI/CD build servers, tighten that to 90 days out of supply-chain caution. There is no active exploitation and no public PoC, so this is a backlog item, not a fire drill.

Sources

  1. MSRC Advisory — CVE-2026-50469
  2. Microsoft — Enabling Windows Projected File System
  3. Huntress — Windows ProjFS Internals: A Technical Deep Dive
  4. Tenable — KB5101649 Nessus Plugin (Windows 11 26H1)
  5. Tenable — July 2026 Patch Tuesday Overview
  6. ZDI — Symlink Privilege Escalation Techniques on Windows
  7. FIRST — EPSS Data and Statistics
Peer Review

What defenders are saying.

Submit a review attribution: handle + country only
0 flags selected · stored anonymously
Validation Results

Crowdsourced verification outputs.

Results submitted by users who ran the verification payload against their environment.