ZeroHour

CVE-2026-71340

mass

Use-After-Free in Windows File History Service Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p19
Published
()
Modified
AI analysis

CVE-2026-71340 is a use-after-free flaw (CWE-416) in the Windows File History Service that allows an authorized attacker to elevate privileges locally. Triggering it requires local access with low privileges, and the high attack complexity (AC:H) means reliable exploitation likely depends on specific timing or system state conditions around the service's memory handling. A successful attacker gains elevated privileges with high impact on confidentiality, integrity, and availability, but no user interaction or remote network access is involved. Any Windows installation with the File History Service is potentially affected; the provided data does not enumerate specific Windows versions or builds, so defenders should consult Microsoft's advisory for exact version ranges. There is no evidence of exploitation so far: no public proof-of-concept, not listed in CISA KEV, and a low EPSS probability of 0.3% over the next 30 days.

What to do: Apply Microsoft's security update addressing CVE-2026-71340 as soon as it is available, and check Microsoft's advisory for the exact affected builds since version ranges were not provided in this data. As an interim mitigation, disable or stop the File History Service (fhsvc) on systems that do not use the feature, and prioritize patching multi-user environments such as terminal/RDS servers and shared workstations where untrusted users hold local accounts. Verify exposure by checking the service state (e.g., sc query fhsvc) on Windows endpoints.

Affected
Microsoft Windows (File History Service)
Estimated exposure
mass≈1 billion Windows client devices ship the File History Service component; realistic exposure is lower, likely hundreds of millions — The File History service (fhsvc) is a standard component of modern Windows client installations, of which roughly a billion-plus devices are in use, though only systems where the service is actually enabled or invoked are realistically…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.