CVE-2026-68837
massUse-after-free privilege elevation in Windows File History Service
CVE-2026-68837 is a use-after-free flaw (CWE-416) in the Windows File History Service that allows an authorized attacker to elevate privileges locally. To trigger it, an attacker must already have a low-privileged account on the target Windows machine and then exploit the memory-handling bug in the service, with no user interaction required. Successful exploitation yields higher local privileges on the compromised host (CVSS impact rated high for confidentiality, integrity, and availability), which an attacker could use to disable security tooling, persist, or pivot further within the environment. Because the attack vector is local and requires prior access, this is an escalation-of-privilege issue rather than a remote entry point, affecting Windows systems running the File History Service. As of now there is no known public proof-of-concept, no CISA KEV listing, and a low predicted exploitation probability (EPSS 0.2%, ~10th percentile), so no in-the-wild exploitation is confirmed.
What to do: Track Microsoft's advisory for CVE-2026-68837 and apply the corresponding security update across Windows endpoints as soon as it is available. Because exploitation requires local access, prioritize shared workstations, multi-user hosts, and systems with untrusted or third-party local accounts in your first patch wave; consider disabling or restricting the File History service (fhsvc) on systems that do not use it as an interim mitigation. No public PoC or KEV listing exists, so standard patch-cadence handling is reasonable, but verify service inventory across your estate.
| Microsoft Windows (File History Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.