Impact
Use after free vulnerability in the Windows Work Folder Service allows an authorized local attacker to elevate privileges. This flaw can lead to arbitrary code execution with SYSTEM rights, compromising confidentiality, integrity, and availability of the affected machine. The weakness is identified as CWE-416, which indicates a use‑after‑free condition that can be abused when the service incorrectly reuses freed memory.
Affected Systems
Affected systems include Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012 R2, 2016, 2019 and 2025. Specific patch levels are not listed, so all builds listed under the vendors are potentially vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates medium‑high risk. EPSS is not reported, and the vulnerability is not listed in CISA KEV, so exploitation is currently considered unlikely but still feasible for privileged local users. The likely attack vector is local, requiring an authorized attacker with the ability to run code that interacts with the Work Folder Service. Exploitation would involve triggering the service's use after free to gain SYSTEM privileges.
OpenCVE Enrichment