Description
Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Published: 2026-08-11
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Windows Bind Filter Driver that allows an authorized local user to execute code with elevated system privileges, enabling a local privilege escalation. The CVE description does not specify the exact trigger mechanism; however, the flaw involves the driver’s handling of network binding objects. Based on the description, it is inferred that an attacker must interact with the Bind Filter Driver in some manner to trigger the use‑after‑free, but the precise conditions or malformed data required are not disclosed.

Affected Systems

Affected systems include Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 and Microsoft Windows Server 2025 (including Server Core installations). These releases rely on the Bind Filter Driver component and are listed by Microsoft as vulnerable.

Risk and Exploitability

The CVSS score of 7.8 indicates a high‑severity local‑privilege capability. The flaw requires local authorization and can be exploited by a legitimate user already present on the system, limiting the attack surface to local accounts. No EPSS score is provided, and the vulnerability is not listed in the CISA KEV catalog, suggesting that documented exploitation is not currently widespread. Nonetheless, local administrators or service accounts that can interact with the driver pose a risk and should be monitored for anomalous behavior.

Generated by OpenCVE AI on August 12, 2026 at 17:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Microsoft security updates that address the bind filter driver issue for Windows 11 (23H2 and newer) and Windows Server 2025.
  • If no update is available yet, restrict local user accounts to only those required for business operations and disable or uninstall any unused network filtering drivers that rely on the Bind Filter component.
  • Consider isolating vulnerable workstations or servers in a separate network segment and monitor for suspicious activity that could indicate exploitation of the use‑after‑free flaw.

Generated by OpenCVE AI on August 12, 2026 at 17:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows Server 2025 (server Core Installation)
Vendors & Products Microsoft windows Server 2025 (server Core Installation)

Thu, 13 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
CPEs cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26h1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1

Tue, 11 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
Description Use after free in Windows Bind Filter Driver allows an authorized attacker to elevate privileges locally.
Title Windows Bind Filter Driver Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 23h2 Windows 11 23h2 Windows 11 24h2 Windows 11 24h2 Windows 11 25h2 Windows 11 25h2 Windows 11 26h1 Windows 11 26h1 Windows Server 2025 Windows Server 2025 (server Core Installation)
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-31T20:04:46.908Z

Reserved: 2026-07-13T04:47:32.464Z

Link: CVE-2026-61934

cve-icon Vulnrichment

Updated: 2026-08-11T18:27:39.689Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-11T17:18:16.473

Modified: 2026-08-13T14:14:10.280

Link: CVE-2026-61934

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:22:19Z

Weaknesses