CVE-2026-69560
nicheUse-after-free local privilege escalation in Microsoft Windows Work Folders Service
Microsoft's Windows Work Folders Service contains a use-after-free memory-corruption flaw (CWE-416) that allows an authorized, low-privileged local user to elevate privileges on the host. Exploitation requires local access and involves triggering the service to use freed memory, with high attack complexity and no user interaction required (AV:L/AC:H/PR:L/UI:N). A successful attacker gains elevated privileges on the local system, with high confidentiality, integrity, and availability impact per the CVSS score of 7.0. Only Windows systems where the Work Folders service or role is enabled are exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; EPSS currently assigns a 0.3% (17th percentile) probability of exploitation within the next 30 days.
What to do: Inventory hosts running the Work Folders service (check the WorkFolders service or the Work Folders server role in Server Manager) and disable the feature where it is not actively used. Apply Microsoft's security update for CVE-2026-69560 via Windows Update/WSUS when available, prioritizing Windows Server file servers that expose Work Folders. Given the local-only, high-complexity attack path and low EPSS score, treat this as a standard-cycle patch rather than an emergency, but do not defer on internet-reachable or multi-user servers.
| Microsoft Windows Work Folders Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.