Junglewise Threat Intelligence

CVE-2026-72947: Microsoft Windows File History Service integer underflow privilege escalation

CVE-2026-72947 · Severity: medium · CVSS 6.4 · Published 2026-09-08

Executive brief

Windows File History Service is a built-in backup component that allows users to maintain versioned copies of their files. An authorized local attacker could exploit an integer underflow vulnerability to elevate their privileges on the system, potentially gaining administrative access and full control over the computer.

Technical details

An integer underflow (wrap or wraparound) vulnerability exists in the Windows File History Service that can be leveraged by an authorized attacker with local access. The vulnerability allows an authenticated user to trigger a memory corruption condition through improper integer handling, leading to privilege escalation from a standard user to a higher privilege level. The attack requires prior authentication and local system access. A patch has been released by Microsoft as indicated by the Security Update Guide reference.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats