Junglewise Threat Intelligence

CVE-2026-69560: Microsoft Windows Work Folder Service use-after-free privilege escalation

CVE-2026-69560 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Work Folder Service is a component that synchronizes work files and documents across devices. A use-after-free vulnerability allows an authorized local user to execute code with elevated system privileges, potentially gaining full control of the affected computer.

Technical details

A use-after-free vulnerability exists in Windows Work Folder Service where memory is accessed after it has been freed, allowing an authenticated local attacker to trigger memory corruption. The vulnerability requires local access and user authentication to exploit. An attacker can leverage this flaw to execute arbitrary code in the context of the System account, achieving privilege escalation from an authorized user to SYSTEM level. A patch is expected to be available from Microsoft.

Affected products

  • Microsoft Windows Work Folder Service

Timeline

  • 2026-09-08: disclosed

References

Related threats