Impact
Windows Work Folder Service contains a use‑after‑free condition where an object is freed and subsequently accessed, enabling an attacker who already has local authorization to execute code with elevated privileges. The flaw is a race condition (CWE‑362) and a use‑after‑free (CWE‑416). The documented impact is local privilege escalation that could give the attacker administrative or kernel‑level rights. The CVE description does not mention a remote or network‑based attack vector, implying that the attack must originate from a user with existing local access to the affected system.
Affected Systems
Affected Windows releases include Windows 10 from Version 1607 to Version 22H2, multiple builds of Windows 11 from Version 23H2 through 26H1 (x86, x64 and arm64 variants), and Windows Server platforms ranging from Server 2012 R2 through Server 2025, including core installations. All affected editions have the Work Folder Service enabled or installed.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity. EPSS is not available, so there is no estimated exploitation probability; the flaw is not listed in CISA’s KEV catalog. Exploitation requires local authorized access and a functional Work Folder Service; an attacker must trigger the use‑after‑free sequence. Given the local nature of the attack, systems that expose the service to users who could have compromised credentials face a high risk of privilege escalation, whereas systems that disable the service or restrict local accounts lower the immediate threat.
OpenCVE Enrichment