Windows Container Isolation Driver Publicly Disclosed Zero-Day Grants Administrator Privileges (CVE-2026-72971)
Scope: Windows 10, Windows 11, Windows Server 2019, 2022, and 2025
Severity: High
Microsoft's August 2026 Patch Tuesday addressed CVE-2026-72971, a publicly disclosed elevation of privilege flaw in the Windows Container Isolation FS Filter Driver (unionfs.sys) that allows an authenticated local attacker with credentials for any other local account to load that account's registry hive via a specially crafted application, granting access to or modification of that user's data and escalating to administrator privileges. Check Point Research has attributed active exploitation of the companion CVE-2026-68820 to North Korea's Lazarus Group in Operation Dream Job, a pattern where this class of driver-level vulnerability is used as the second stage of targeted attacks following initial access via phishing lures. Organizations must apply the August 2026 cumulative update immediately, enforce least privilege access policies to limit the blast radius of any compromised local account, and monitor for unusual registry hive loading activity on shared workstations and server environments.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.