ZeroHour

CVE-2026-80075

large

Local Privilege Elevation via Heap Buffer Overflow in Windows Work Folders

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-80075 is a heap-based buffer overflow (CWE-122) in the Windows Work Folders component of Windows Server. A local, authorized (low-privileged) attacker can trigger the overflow through the Work Folders feature without any user interaction. Successful exploitation lets the attacker elevate privileges on the host, with high impact on confidentiality, integrity, and availability of the affected system. Only organizations that have enabled the Work Folders role on their Windows Servers are affected; standard Windows clients without this role are not implicated by this flaw. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%.

What to do: Inventory Windows Servers for the Work Folders role and prioritize any host running it, then apply the Microsoft security update addressing CVE-2026-80075 via Windows Update or the Microsoft Update Catalog. If patching must be delayed, reduce exposure by restricting interactive/local logon rights on Work Folders servers to trusted, low-risk accounts, since exploitation requires a local authorized account and no user interaction. Monitor Microsoft's advisory for affected build ranges and any updates to exploitation status.

Affected
Microsoft Windows Work Folders (Windows Server role)
Estimated exposure
largeon the order of tens of thousands of Windows Server deployments worldwide (estimate) — Work Folders is an optional Windows Server file-sync role typically deployed on only one or a few servers per enterprise, so the affected population is a small fraction of the multi-million-unit Windows Server installed base, roughly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 21h2, windows 10 22h2, windows 11 24h2, windows 11 25h2, windows 11 26h1
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.