cbcvebase.
CVE-2026-25167
published 2026-03-10

CVE-2026-25167: Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

high7.4CVSS 3.1
AVLACHPRNUINSUCHIHAH
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.

Affected

15 ranges
VendorProductVersion rangeFixed in
microsoftwindows_11_24h2< 10.0.26100.797910.0.26100.7979
microsoftwindows_11_25h2< 10.0.26200.797910.0.26200.7979
microsoftwindows_11_26h1< 10.0.28000.171910.0.28000.1719
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.803710.0.26100.8037
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.803710.0.26200.8037
microsoftwindows_11_version_26h1>= 10.0.28000.0 < 10.0.28000.171910.0.28000.1719
microsoftwindows_server_2025< 10.0.26100.3246310.0.26100.32463
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.3252210.0.26100.32522
msrcwindows_11_version_24h2_for_arm64-based_systems
msrcwindows_11_version_24h2_for_x64-based_systems
msrcwindows_11_version_25h2_for_arm64-based_systems
msrcwindows_11_version_25h2_for_x64-based_systems
msrcwindows_11_version_26h1_for_arm64-based_systems
msrcwindows_11_version_26h1_for_x64-based_systems
msrcwindows_server_2025