Executive brief
Windows Distributed File System (DFS) is a Microsoft component that allows organizations to organize shared files and folders across multiple servers. A use-after-free vulnerability allows an authorized attacker to crash the DFS service, disrupting access to shared files and causing operational downtime for dependent systems and users.
Technical details
A use-after-free vulnerability exists in Windows Distributed File System due to improper memory management of freed objects. An authenticated attacker with network access to a DFS-enabled system can trigger the vulnerability by sending specially crafted network requests, causing the DFS service to reference already-freed memory. This leads to a denial-of-service condition affecting the availability of file shares and DFS operations. The vulnerability requires prior authentication and network reachability to the affected DFS server.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed