Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4785 articles · 193733 vulns · 37/41 feeds (7d)
← Back to list
7.8
CVE-2026-45586KEVEXPLOITEDPATCHED
microsoft · windows_10_1607

Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability

Description

Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.

Affected Products

VendorProductVersions
microsoftwindows_10_160710.0.14393.0, 10.0.17763.0, 10.0.19044.0, 10.0.19045.0, 10.0.22631.0, 10.0.22631.0, 10.0.26100.0, 10.0.26200.0, 10.0.28000.0, 6.2.9200.0, 6.2.9200.0, 6.3.9600.0, 6.3.9600.0, 10.0.14393.0, 10.0.14393.0, 10.0.17763.0, 10.0.17763.0, 10.0.20348.0, 10.0.26100.0, 10.0.26100.0

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
microsoftwindows 10 versionmitre_affected90%
microsoftwindows server 2012 r2mitre_affected90%
microsoftwindows 10 version 21h2mitre_affected90%
microsoftwindows server 2012 r2 (server core installation)mitre_affected90%
microsoftwindows 11 version 25h2mitre_affected90%

References

  • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-45586(vendor-advisory, patch)

Related News (12 articles)

Tier E
Hacker News5h ago
New Nightmare Eclipse zero day gives system privileges on patched Windows
→ No new info (linked only)
Tier D
CSO Online69d ago
June Patch Tuesday marks a ‘new normal’ with over 200 CVEs, 32 rated ‘critical’
→ No new info (linked only)
Tier D
SecurityWeek69d ago
New Windows Zero-Day Exploit ‘RoguePlanet’ Released
→ No new info (linked only)
Tier D
Help Net Security69d ago
Record Microsoft Patch Tuesday, fresh zero-day
→ No new info (linked only)
Tier D
The Hacker News69d ago
Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
→ No new info (linked only)
Tier D
Infosecurity Magazine69d ago
Microsoft Fixes 200 CVEs in June Patch Tuesday
→ No new info (linked only)
Tier B
CERT-FR69d ago
Multiples vulnérabilités dans Microsoft Windows (10 juin 2026)
→ No new info (linked only)
Tier C
Qualys Blog70d ago
Microsoft and Adobe Patch Tuesday, June 2026 Security Update Review
→ No new info (linked only)
Tier C
VulDB70d ago
CVE-2026-45586 | Microsoft Windows up to Server 2025 Collaborative Translation Framework link following
→ No new info (linked only)
Tier D
BleepingComputer70d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
→ No new info (linked only)
Tier A
Microsoft MSRC70d ago
CVE-2026-45586 Windows Collaborative Translation Framework (CTFMON) Elevation of Privilege Vulnerability
→ No new info (linked only)
Tier C
CrowdStrike Blog70d ago
June 2026 Patch Tuesday: Microsoft Patches 206 Vulnerabilities Including Three Publicly Disclosed Zero-Days
→ No new info (linked only)
CVSS 3.17.8 HIGH
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CISA KEV✅ Yes
Actively exploited✅ Yes
Patch available
10.0.14393.923410.0.17763.888010.0.19044.741710.0.19045.741710.0.22631.721910.0.26100.865510.0.26200.865510.0.28000.22696.2.9200.261326.3.9600.2322810.0.20348.525610.0.26100.32995
CWECWE-59
PublishedJun 9, 2026
Last enriched70d agov3
Tags
CVE-2026-45586
Trending Score139🔥
Source articles12
Independent12
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-68820EXPKEV
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Trending: 155
HIGHCVE-2026-45659EXPKEV
Microsoft SharePoint Remote Code Execution Vulnerability
Trending: 148
CRITICALCVE-2026-55040EXPKEV
Microsoft SharePoint Server Security Feature Bypass Vulnerability
Trending: 132
HIGHCVE-2026-63520
Microsoft SharePoint Server Remote Code Execution Vulnerability
Trending: 60
MEDIUMCVE-2026-50661
Windows BitLocker Security Feature Bypass Vulnerability
Trending: 57

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jun 9, 2026
Added to CISA KEV
Jun 9, 2026
Discovered by ZDM
Jun 9, 2026
Updated: description, exploitAvailable, activelyExploited
Jun 9, 2026
Updated: tags
Jun 9, 2026
Actively Exploited
Aug 14, 2026
Exploit Available
Aug 14, 2026
Patch Available
Aug 14, 2026

Version History

v3
Last enriched 70d ago
v3Tier C70d ago

Updated severity to CRITICAL and added new CVE ID CVE-2026-45586.

tags
via VulDB
v2Tier A70d ago

Added a detailed description of the vulnerability and marked it as actively exploited with an exploit available.

descriptionexploitAvailableactivelyExploited
via Microsoft MSRC
v170d ago

Initial creation