Executive brief
Windows Work Folder Service is a Microsoft component that synchronizes files between devices and servers for enterprise users. An integer overflow vulnerability in this service allows authorized attackers to execute arbitrary code on affected systems over the network, potentially leading to system compromise and data theft.
Technical details
This vulnerability is an integer overflow or wraparound flaw in Windows Work Folder Service that permits remote code execution. The attack requires network access and attacker authorization (authentication credentials or elevated privilege), but does not require user interaction. Successful exploitation allows an authorized attacker to execute arbitrary code with the privileges of the affected service, potentially leading to full system compromise. Microsoft has issued patches for this vulnerability; consult the security update guide for affected Windows versions and remediation steps.
Affected products
- Microsoft Windows Work Folder Service <UNKNOWN>
Timeline
- 2026-09-08: disclosed