Junglewise Threat Intelligence

CVE-2026-34340: Microsoft Windows Projected File System use after free privilege escalation

CVE-2026-34340 · Severity: high · CVSS 7 · Published 2026-05-12

Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Projected File System, a component that allows applications to provide virtual files and directories to the operating system. An attacker who already has limited access to a computer could exploit this flaw to gain full administrative control. This could lead to the unauthorized access of sensitive data, the installation of malicious software, or the disruption of business operations.

Technical details

A use-after-free vulnerability (CWE-416) exists within the Windows Projected File System (ProjFS) driver. The flaw is triggered when the system continues to use a memory pointer after it has been freed, leading to memory corruption. To exploit this, an attacker must have local access to the system with low-level privileges and successfully win a race condition or manipulate memory timing (indicated by the High Attack Complexity). Successful exploitation allows the attacker to execute code with elevated system privileges, bypassing security boundaries. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Projected File System (ProjFS)

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References