This post has been republished via RSS; it originally appeared at: MSRC Security Update Guide.
Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.