Description
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Microsoft Brokering File System contains a use‑after‑free flaw that an authorized local user can exploit to gain elevated privileges. The vulnerability, identified as CWE‑416, permits the attacker to access or execute memory that has already been freed, potentially allowing the execution of malicious code with higher privileges. Because the flaw resides in the kernel‑level file‑system component, the impact is confined to the compromised machine and requires no network access.

Affected Systems

The flaw affects Microsoft Windows 11 operating systems released as versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025, including the Server Core installation. These releases are identified by the vendor and product names and their associated version numbers in the provided list.

Risk and Exploitability

The CVSS score of 7.0 indicates a moderate severity rating, while the EPSS score of less than 1% signals a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is local, requiring an authorized user to trigger the use‑after‑free within the brokering file system to elevate privileges.

Generated by OpenCVE AI on August 1, 2026 at 09:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest cumulative update from Microsoft that contains the fix for CVE‑2026‑49162 on all affected Windows 11 and Windows Server 2025 installations, which addresses the use‑after‑free (CWE‑416).
  • Disable or restrict local user accounts that have unnecessary write access to the brokering file system, ensuring that only privileged users can interact with components that may trigger the flaw.
  • Enable core isolation and virtualization-based security features to help contain kernel memory corruption attempts and monitor system logs for anomalous activity that could indicate an attack attempt.

Generated by OpenCVE AI on August 1, 2026 at 09:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
Title Microsoft Brokering File System Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:22:09.223Z

Reserved: 2026-05-27T23:44:09.622Z

Link: CVE-2026-49162

cve-icon Vulnrichment

Updated: 2026-07-15T11:01:21.718Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T10:00:04Z

Weaknesses