CVE-2026-61349 — Windows Work Folder Service Elevation of Privilege Vulnerability
Executive Summary
Use after free in Windows Work Folder Service allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Use-after-free (CWE-416) via a race (CWE-362) in the Windows Work Folders service workfolderssvc.dll SyncShare partnership-manager connection point, local EoP to SYSTEM. workfolderssvc.dll exposes CSyncSharePartnershipManagerInternal, a COM connection point (IConnectionPointImpl) whose clients Advise (register a notification sink) and Unadvise (unregister). PRE: access to the connection point's sink list in Advise/Unadvise was not synchronized against concurrent Advise/Unadvise or notification dispatch, so a racing Unadvise could free a sink while another path (a concurrent Advise, or a notification being delivered) still referenced it - a use-after-free of the sink/partner object. Because the service runs as SYSTEM and the Advise/Unadvise interface is reachable by a local user, winning the race is a local EoP-to-SYSTEM primitive. Diff of workfolderssvc.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flag Feature_4078422328, CSyncSharePartnershipManagerInternal::Advise and ::Unadvise are reworked to serialize access to the connection-point sink list with an exclusive lock (a lock_exclusive / SRW-lock guard is introduced and used, with associated RAII lock wrappers added) before registering/unregistering the sink, so a sink cannot be freed while another Advise/Unadvise or dispatch path is using it, closing the race/UAF.
| Function | Address | Change | Note |
|---|---|---|---|
CSyncSharePartnershipManagerInternal::Advise |
code change |
code (sink registration serialized under exclusive lock, CFR-gated) | Post (Feature_4078422328): Advise takes an exclusive lock (lock_exclusive) around IConnectionPointImpl::Advise (adding the sink to the connection-point list) so registration is serialized against Unadvise/dispatch. |
CSyncSharePartnershipManagerInternal::Unadvise |
code change |
code (sink removal serialized under exclusive lock, CFR-gated) | Post (Feature_4078422328): Unadvise takes the same exclusive lock around IConnectionPointImpl::Unadvise (removing/freeing the sink) so a sink is not freed while another path holds it. |
lock_exclusive / RAII lock wrappers |
added |
added | An exclusive-lock helper and associated RAII guards are introduced and used to serialize the connection-point sink-list access (~48 added functions include the lock/wrapper machinery). |
Feature_4078422328 |
gate |
added (CFR gate) | CFR flag gating the lock-serialized Advise/Unadvise; the original unsynchronized path still ships when disabled. |
Attack Path
Concurrent Advise/Unadvise on the Work Folders sync connection point frees a sink while another path uses it
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Jongseong Kim (nevul37), SEC-agent team
Hwiwon Lee (hwiwonl), SEC-agent team
Younggi Park (grill66), SEC-agent team
Dongjun Kim (smlijun), SEC-agent team