# CVE-2026-61349 — Windows Work Folders Service `workfolderssvc.dll` Unsynchronized `Advise`/`Unadvise` on the SyncShare Connection Point → Use-After-Free

---

## Summary

| | |
|---|---|
| **Product** | Windows — `workfolderssvc.dll` (Windows Work Folders Service, runs as SYSTEM) |
| **CVE ID** | CVE-2026-61349 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.8 / 6.8 — `CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-416: Use After Free + CWE-362: Race Condition |
| **Delivery** | Local — concurrent `Advise`/`Unadvise` on the SyncShare connection point |
| **KB / Fixed build** | KB5121003 — `workfolderssvc.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `workfolderssvc.dll` 10.0.26100.8972 — SHA256 `42fe9ea2296ada42bb8e0116ce00ab533f1bd66dcbf2279c57f256770446333f` |
| **Post-patch binary** | `workfolderssvc.dll` 10.0.26100.9168 — SHA256 `d969215670e5788b28e5a09631a00ba0e727c8febac2e2253690ab87c08bdba1` |
| **Feature flag** | `Feature_4078422328` — **the fix is CFR-gated** |
| **Exploitability** | Exploitation Unlikely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`workfolderssvc.dll` implements the Windows **Work Folders** service (SYSTEM). It
exposes `CSyncSharePartnershipManagerInternal`, a COM **connection point**
(`IConnectionPointImpl`) that manages sync-share partnerships: clients call `Advise`
to register a notification **sink** and `Unadvise` to unregister it.

---

## Vulnerability Summary

Pre-patch, `Advise` and `Unadvise` accessed the connection point's **sink list
without synchronization**. Concurrent `Advise`/`Unadvise` calls — or an `Unadvise`
racing a notification being dispatched — could therefore run at once, so a racing
`Unadvise` could free a sink while another path (a concurrent `Advise`, or an
in-flight dispatch) still referenced it: a use-after-free of the sink/partner object
(CWE-416, triggered by the race, CWE-362). Because the service runs as **SYSTEM** and
the `Advise`/`Unadvise` interface is reachable by a local user, winning the race is a
local elevation-of-privilege primitive to SYSTEM (per the MSRC FAQ).

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`, `AC:L`): drive the Work Folders SyncShare
  partnership manager's `Advise`/`Unadvise`.
- Issue concurrent `Advise`/`Unadvise` (or race a notification dispatch) on the same
  connection point.
- Result: a sink is freed while another path is using it.

---

## Vulnerability Details

### Root Cause

The connection-point sink list was mutated by `Advise`/`Unadvise` without a lock, so
`Unadvise` could free a sink concurrently held/used by another `Advise` or a
dispatch.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_4078422328`, `CSyncSharePartnershipManagerInternal::Advise` and
`::Unadvise` are reworked to **serialize the sink-list access under an exclusive
lock** — an `lock_exclusive` / SRW-lock guard (with associated RAII lock wrappers) is
introduced and taken around the `IConnectionPointImpl::Advise` / `Unadvise` sink
registration/removal:

```c
// CSyncSharePartnershipManagerInternal::Advise / Unadvise (10.0.26100.9168) — PATCHED (from the diff)
if (Feature_4078422328__private_IsEnabled()) {
    auto guard = lock_exclusive(&this->m_lock);          // *** serialize sink-list access ***
    IConnectionPointImpl<CSyncSharePartnershipManagerInternal, ...>::Advise/Unadvise(...);
}
```

With `Advise` and `Unadvise` holding the exclusive lock while adding/removing a sink,
a sink can no longer be freed while another `Advise`/`Unadvise` or dispatch path is
using it, closing the race and the use-after-free.

### Patch Completeness Assessment

**CFR-gated behind `Feature_4078422328`.** The lock-serialized `Advise`/`Unadvise`
runs only when the flag is enabled; the original unsynchronized path still ships when
disabled. Verify `Feature_4078422328` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Rapid/concurrent `Advise`/`Unadvise` against the Work Folders
SyncShare partnership manager; use-after-free / heap-corruption bugchecks in
`workfolderssvc!CSyncSharePartnershipManagerInternal::Advise` / `::Unadvise` within
the SYSTEM Work Folders service on unpatched/flag-disabled builds.

**Config.** The fix is CFR-gated — confirm `Feature_4078422328` is enabled.

---

## References

- MSRC advisory — CVE-2026-61349 (Windows Work Folder Service Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/workfolderssvc_dll-cve-2026-61349-ghidriff.md`
