Junglewise Threat Intelligence

CVE-2026-71340: Microsoft Windows File History Service use-after-free privilege escalation

CVE-2026-71340 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows File History Service is a Windows component that automatically backs up user files. A use-after-free vulnerability in this service allows an authenticated attacker with local access to elevate their privileges to system or administrator level, potentially gaining full control of the affected computer.

Technical details

The vulnerability is a use-after-free flaw in the Windows File History Service. An authorized local attacker can exploit this memory safety issue to execute arbitrary code with elevated privileges. The attack requires local access and an existing user account on the target system. Successful exploitation leads to privilege escalation from an unprivileged user context to SYSTEM or administrator privileges. A security patch is available from Microsoft.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats