ZeroHour

CVE-2026-68837

mass

Use-after-free privilege elevation in Windows File History Service

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-68837 is a use-after-free flaw (CWE-416) in the Windows File History Service that allows an authorized attacker to elevate privileges locally. To trigger it, an attacker must already have a low-privileged account on the target Windows machine and then exploit the memory-handling bug in the service, with no user interaction required. Successful exploitation yields higher local privileges on the compromised host (CVSS impact rated high for confidentiality, integrity, and availability), which an attacker could use to disable security tooling, persist, or pivot further within the environment. Because the attack vector is local and requires prior access, this is an escalation-of-privilege issue rather than a remote entry point, affecting Windows systems running the File History Service. As of now there is no known public proof-of-concept, no CISA KEV listing, and a low predicted exploitation probability (EPSS 0.2%, ~10th percentile), so no in-the-wild exploitation is confirmed.

What to do: Track Microsoft's advisory for CVE-2026-68837 and apply the corresponding security update across Windows endpoints as soon as it is available. Because exploitation requires local access, prioritize shared workstations, multi-user hosts, and systems with untrusted or third-party local accounts in your first patch wave; consider disabling or restricting the File History service (fhsvc) on systems that do not use it as an interim mitigation. No public PoC or KEV listing exists, so standard patch-cadence handling is reasonable, but verify service inventory across your estate.

Affected
Microsoft Windows (File History Service)
Estimated exposure
mass≈hundreds of millions to 1 billion+ Windows endpoints (File History Service ships with Windows client editions) — The vulnerable component is a service included with Windows, whose installed base exceeds one billion devices per widely cited market-share figures, though exploitability requires a local low-privileged attacker.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.