ZeroHour

CVE-2026-71336

niche

Integer Overflow RCE in Microsoft Windows Work Folders Service

CVSS 3.1
8.8 high
EPSS
<1%p56
Published
()
Modified
AI analysis

CVE-2026-71336 is an integer overflow/wraparound flaw (CWE-190) in the Windows Work Folders service that Microsoft characterizes as an authenticated remote code execution vulnerability. An attacker who already holds valid low-privilege credentials can trigger the overflow by sending crafted requests to the service over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the Work Folders service, with high impact on confidentiality, integrity, and availability of the host. Affected systems are Windows deployments where the Work Folders feature is in use — typically Windows Server machines acting as Work Folders sync servers, since this is an optional role — though the available data does not specify exact affected version ranges. As of this analysis there is no public proof-of-concept, the flaw is not in CISA's Known Exploited Vulnerabilities catalog, and EPSS assigns only about a 0.9% probability of exploitation within 30 days (56th percentile).

What to do: Inventory systems with the Work Folders role enabled and prioritize applying Microsoft's security update for this CVE as soon as patched builds are published, since no version numbers are included here. Meanwhile, restrict network access to the Work Folders endpoints to trusted networks and limit which accounts can reach the service, given the low-privilege authenticated attack requirement. Monitor Microsoft's advisory for affected-version details and check the service's exposure for internet-reachable instances.

Affected
Microsoft Windows Work Folders Service
Estimated exposure
nicheunknown, likely limited to tens of thousands of servers at most (Work Folders is an optional Windows Server role, not enabled by default) — No install or scan counts are provided, but Work Folders is an opt-in server role that is rarely deployed and typically exposed only internally rather than on the public internet, so exposure is plausibly far below Windows' overall…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer overflow or wraparound in Windows Work Folder Service allows an authorized attacker to execute code over a network.

Weakness
CWE-190
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.