Elevation of Privileges in Microsoft Brokering File System
CVE-2026-50458

7.8HIGH

Key Information:

Badges

πŸ“ˆ Score: 799πŸ‘Ύ Exploit ExistsπŸ“° News Worthy

What is CVE-2026-50458?

CVE-2026-50458 is a vulnerability identified in the Microsoft Brokering File System, a component that facilitates the management and access of file resources within a networked environment. This vulnerability arises from a "use after free" error, which occurs when a program continues to reference a memory location after it has been freed. As a result, an authorized attacker could exploit this flaw to elevate their privileges on the local system. This could have significant consequences for various organizations, as it may allow unauthorized users to gain elevated access rights, thereby compromising sensitive information, executing malicious operations, or altering critical system configurations without authorization.

Potential impact of CVE-2026-50458

  1. Unauthorized Access: The primary risk associated with this vulnerability is the potential for unauthorized users to gain elevated privileges. This could lead to access to restricted data and sensitive systems, undermining the security of organizational information.

  2. System Compromise: Exploitation of this vulnerability could result in a complete compromise of affected systems, allowing attackers to install malware, exfiltrate data, or alter system configurations, destabilizing the overall IT stability.

  3. Increased Attack Surface: With the potential for privilege elevation, the existence of this vulnerability could expand the attack surface for threat actors. If exploited, it may serve as a gateway for further attacks, leading to more severe incidents, including data breaches and propagation of malware throughout an organization's network.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.8875

Windows 11 Version 25H2 ARM64-based Systems 10.0.26200.0 < 10.0.26200.8875

Windows 11 version 26H1 ARM64-based Systems 10.0.28000.0 < 10.0.28000.2525

News Articles

Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability

Windows 11 and Server 2025 are affected by a high-severity Brokering File System vulnerability that enables local privilege escalation.

1 week ago

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ“°

    First article discovered by Cybersecuritynews

  • Vulnerability published

  • Vulnerability Reserved

.