CVE-2026-80075
largeLocal Privilege Elevation via Heap Buffer Overflow in Windows Work Folders
CVE-2026-80075 is a heap-based buffer overflow (CWE-122) in the Windows Work Folders component of Windows Server. A local, authorized (low-privileged) attacker can trigger the overflow through the Work Folders feature without any user interaction. Successful exploitation lets the attacker elevate privileges on the host, with high impact on confidentiality, integrity, and availability of the affected system. Only organizations that have enabled the Work Folders role on their Windows Servers are affected; standard Windows clients without this role are not implicated by this flaw. As of this analysis there is no known exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3%.
What to do: Inventory Windows Servers for the Work Folders role and prioritize any host running it, then apply the Microsoft security update addressing CVE-2026-80075 via Windows Update or the Microsoft Update Catalog. If patching must be delayed, reduce exposure by restricting interactive/local logon rights on Work Folders servers to trusted, low-risk accounts, since exploitation requires a local authorized account and no user interaction. Monitor Microsoft's advisory for affected build ranges and any updates to exploitation status.
| Microsoft Windows Work Folders (Windows Server role) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Work Folders allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 21h2, windows 10 22h2, windows 11 24h2, windows 11 25h2, windows 11 26h1
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.