Important CVSS 7.8 EPSS 0.00238 🔬 Patch diffed 2026-08 archive

Executive Summary

Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Exploitation Unlikely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00238 — 0.15019 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.00238
probability of exploitation in the next 30 days
0.15019 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

20 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 R2 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5120238 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Elevation of Privilege Yes

Patches

6 patches
Article Type Restart
5120418 Security Update Yes
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes
5120385 Monthly Rollup Yes

Patch Diff

ghidriff · workfolderssvc.dll (KB5121003)

Use-after-free (CWE-416) via a race (CWE-362) in the Windows Work Folders service workfolderssvc.dll SyncShare partnership-manager connection point, local EoP to SYSTEM. workfolderssvc.dll exposes CSyncSharePartnershipManagerInternal, a COM connection point (IConnectionPointImpl) whose clients Advise (register a notification sink) and Unadvise (unregister). PRE: access to the connection point's sink list in Advise/Unadvise was not synchronized against concurrent Advise/Unadvise or notification dispatch, so a racing Unadvise could free a sink while another path (a concurrent Advise, or a notification being delivered) still referenced it - a use-after-free of the sink/partner object. Because the service runs as SYSTEM and the Advise/Unadvise interface is reachable by a local user, winning the race is a local EoP-to-SYSTEM primitive. Diff of workfolderssvc.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_4078422328, CSyncSharePartnershipManagerInternal::Advise and ::Unadvise are reworked to serialize access to the connection-point sink list with an exclusive lock (a lock_exclusive / SRW-lock guard is introduced and used, with associated RAII lock wrappers added) before registering/unregistering the sink, so a sink cannot be freed while another Advise/Unadvise or dispatch path is using it, closing the race/UAF.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
CSyncSharePartnershipManagerInternal::Advise code change code (sink registration serialized under exclusive lock, CFR-gated) Post (Feature_4078422328): Advise takes an exclusive lock (lock_exclusive) around IConnectionPointImpl::Advise (adding the sink to the connection-point list) so registration is serialized against Unadvise/dispatch.
CSyncSharePartnershipManagerInternal::Unadvise code change code (sink removal serialized under exclusive lock, CFR-gated) Post (Feature_4078422328): Unadvise takes the same exclusive lock around IConnectionPointImpl::Unadvise (removing/freeing the sink) so a sink is not freed while another path holds it.
lock_exclusive / RAII lock wrappers added added An exclusive-lock helper and associated RAII guards are introduced and used to serialize the connection-point sink-list access (~48 added functions include the lock/wrapper machinery).
Feature_4078422328 gate added (CFR gate) CFR flag gating the lock-serialized Advise/Unadvise; the original unsynchronized path still ships when disabled.
View full diff report View RCA report

Attack Path

Concurrent Advise/Unadvise on the Work Folders sync connection point frees a sink while another path uses it

Attack path for CVE-2026-61349 Concurrent Advise/Unadvise on the Work Folders sync connection point frees a sink while another path uses it 01 — ENTRY Local user drives the Work Folders SyncShare partnership manager workfolderssvc.dll (SYSTEM) CSyncSharePartnershipManagerInternal exposes Advise/Unadvise (register/unregister a notification sink). AV:L/PR:L/AC:L. 02 — CONTROLLED INPUT Issues concurrent Advise/Unadvise (or races a notification dispatch) Two operations touch the connection-point sink list at once. 03 — MISSING CHECK Sink-list access unsynchronized (CWE-362 -> CWE-416) A racing Unadvise frees a sink while a concurrent Advise / dispatch still references it -> use-after-free. 04 — PATH Freed sink/partner object is dereferenced in the SYSTEM service Controlling the freed/reused allocation influences SYSTEM-side state. 05 — PRIMITIVE Use-after-free in the SYSTEM Work Folders service -> EoP to SYSTEM The Aug 2026 fix (Feature_4078422328) serializes Advise/Unadvise with an exclusive lock.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules