ZeroHour

CVE-2026-69560

niche

Use-after-free local privilege escalation in Microsoft Windows Work Folders Service

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

Microsoft's Windows Work Folders Service contains a use-after-free memory-corruption flaw (CWE-416) that allows an authorized, low-privileged local user to elevate privileges on the host. Exploitation requires local access and involves triggering the service to use freed memory, with high attack complexity and no user interaction required (AV:L/AC:H/PR:L/UI:N). A successful attacker gains elevated privileges on the local system, with high confidentiality, integrity, and availability impact per the CVSS score of 7.0. Only Windows systems where the Work Folders service or role is enabled are exposed. No public proof-of-concept, in-the-wild exploitation, or CISA KEV listing is known; EPSS currently assigns a 0.3% (17th percentile) probability of exploitation within the next 30 days.

What to do: Inventory hosts running the Work Folders service (check the WorkFolders service or the Work Folders server role in Server Manager) and disable the feature where it is not actively used. Apply Microsoft's security update for CVE-2026-69560 via Windows Update/WSUS when available, prioritizing Windows Server file servers that expose Work Folders. Given the local-only, high-complexity attack path and low EPSS score, treat this as a standard-cycle patch rather than an emergency, but do not defer on internet-reachable or multi-user servers.

Affected
Microsoft Windows Work Folders Service
Estimated exposure
nichelikely limited to enterprise deployments with Work Folders enabled — on the order of tens of thousands of systems at most; exact count unknown — Work Folders is an optional Windows Server role/client sync feature that is not enabled by default and has been largely displaced by cloud sync services, so the vulnerable population is only hosts with the service enabled; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.