Description
Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
Published: 2026-09-08
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free vulnerability in the Windows File History Service lets an authorized local user trigger a memory mismanagement that can lead to execution of code with elevated privileges. The flaw, classified as CWE‑416, allows the attacker to obtain SYSTEM rights after interacting with the service following a deallocation event.

Affected Systems

The flaw impacts Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server 2016 and 2019, including their Server Core installations, as listed by the CNA.

Risk and Exploitability

The CVSS score of 7 indicates a high severity issue. No EPSS value is available, so the current exploitation probability is unknown. The attack requires a local attacker with sufficient privileges to interact with the File History Service, limiting the threat surface. The vulnerability is not currently listed in the CISA KEV catalog, suggesting no widespread exploitation has been reported yet.

Generated by OpenCVE AI on September 8, 2026 at 19:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the Microsoft security update that addresses CVE‑2026‑68837 as soon as it becomes available.
  • Disable or restrict the File History Service, ensuring it runs only for trusted accounts if the patch cannot be applied immediately.
  • Maintain all systems with the latest Windows updates and monitor Microsoft advisory releases for additional remediation information.
  • Limit local user privileges to reduce the ability of an attacker to trigger the flaw, ensuring that only authorized system services can interact with File History.

Generated by OpenCVE AI on September 8, 2026 at 19:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description Use after free in Windows File History Service allows an authorized attacker to elevate privileges locally.
Title Windows File History Service Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
Weaknesses CWE-416
CPEs cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_21H2:*:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows_10_22H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23H2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 10 1607
Microsoft windows 10 1809
Microsoft windows 10 21h2
Microsoft windows 10 22h2
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2016
Microsoft windows Server 2019
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 10 1607 Windows 10 1809 Windows 10 21h2 Windows 10 22h2 Windows 11 23h2 Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2016 Windows Server 2019
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-09-08T19:21:17.406Z

Reserved: 2026-07-31T16:47:02.144Z

Link: CVE-2026-68837

cve-icon Vulnrichment

Updated: 2026-09-08T18:59:28.756Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T18:18:31.253

Modified: 2026-09-08T20:17:41.390

Link: CVE-2026-68837

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T20:00:12Z

Weaknesses