CVE-2026-71340
massUse-After-Free in Windows File History Service Enables Local Privilege Escalation
CVE-2026-71340 is a use-after-free flaw (CWE-416) in the Windows File History Service that allows an authorized attacker to elevate privileges locally. Triggering it requires local access with low privileges, and the high attack complexity (AC:H) means reliable exploitation likely depends on specific timing or system state conditions around the service's memory handling. A successful attacker gains elevated privileges with high impact on confidentiality, integrity, and availability, but no user interaction or remote network access is involved. Any Windows installation with the File History Service is potentially affected; the provided data does not enumerate specific Windows versions or builds, so defenders should consult Microsoft's advisory for exact version ranges. There is no evidence of exploitation so far: no public proof-of-concept, not listed in CISA KEV, and a low EPSS probability of 0.3% over the next 30 days.
What to do: Apply Microsoft's security update addressing CVE-2026-71340 as soon as it is available, and check Microsoft's advisory for the exact affected builds since version ranges were not provided in this data. As an interim mitigation, disable or stop the File History Service (fhsvc) on systems that do not use the feature, and prioritize patching multi-user environments such as terminal/RDS servers and shared workstations where untrusted users hold local accounts. Verify exposure by checking the service state (e.g., sc query fhsvc) on Windows endpoints.
| Microsoft Windows (File History Service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2016, windows server 2019
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.