Elevation of Privilege in Microsoft Brokering File System
CVE-2026-25167
7.4HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 March 2026
What is CVE-2026-25167?
A vulnerability in Microsoft Brokering File System has been identified, allowing unauthorized users to gain elevated privileges locally through a use-after-free condition. This security flaw can lead to potential system compromise, making it essential for users to apply the latest security patches provided by Microsoft to mitigate risks.
Affected Version(s)
Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.8037
Windows 11 Version 25H2 10.0.26200.0 < 10.0.26200.8037
Windows 11 version 26H1 ARM64-based Systems 10.0.28000.0 < 10.0.28000.1719