CVE-2026-71336
nicheInteger Overflow RCE in Microsoft Windows Work Folders Service
CVE-2026-71336 is an integer overflow/wraparound flaw (CWE-190) in the Windows Work Folders service that Microsoft characterizes as an authenticated remote code execution vulnerability. An attacker who already holds valid low-privilege credentials can trigger the overflow by sending crafted requests to the service over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the Work Folders service, with high impact on confidentiality, integrity, and availability of the host. Affected systems are Windows deployments where the Work Folders feature is in use — typically Windows Server machines acting as Work Folders sync servers, since this is an optional role — though the available data does not specify exact affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only about a 0.9% probability of exploitation within 30 days (56th percentile).
What to do: Inventory systems with the Work Folders role enabled and prioritize applying Microsoft's security update for this CVE as soon as patched builds are published, since no version numbers are included here. Meanwhile, restrict network access to the Work Folders endpoints to trusted networks and limit which accounts can reach the service, given the low-privilege authenticated attack requirement. Monitor Microsoft's advisory for affected-version details and check the service's exposure for internet-reachable instances.
| Microsoft Windows Work Folders Service | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.
- Weakness
- CWE-190
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.