Junglewise Threat Intelligence

CVE-2026-78446: Microsoft Windows Distributed File System use-after-free

CVE-2026-78446 · Severity: medium · CVSS 5.3 · Published 2026-09-08

Executive brief

Windows Distributed File System (DFS) is a Microsoft component that allows organizations to organize shared files and folders across multiple servers. A use-after-free vulnerability allows an authorized attacker to crash the DFS service, disrupting access to shared files and causing operational downtime for dependent systems and users.

Technical details

A use-after-free vulnerability exists in Windows Distributed File System due to improper memory management of freed objects. An authenticated attacker with network access to a DFS-enabled system can trigger the vulnerability by sending specially crafted network requests, causing the DFS service to reference already-freed memory. This leads to a denial-of-service condition affecting the availability of file shares and DFS operations. The vulnerability requires prior authentication and network reachability to the affected DFS server.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats