CVE-2026-32078

7.8

Microsoft · Windows Projected File System

A use after free vulnerability in the Windows Projected File System allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A high severity use after free vulnerability in the Windows Projected File System enables an authenticated attacker to elevate privileges on affected systems.

Vulnerability

This flaw is a use after free vulnerability (CWE-416) within the Windows Projected File System. It requires the attacker to have local access and low privileges to trigger the condition, potentially resulting in elevated system privileges.

Business impact

The successful exploitation of this vulnerability allows a local user to gain unauthorized administrative or system level control over the host. Given the CVSS score of 7.8, this represents a significant risk to the integrity and confidentiality of the affected machine. Such access could lead to total compromise of the host system, facilitating lateral movement or data exfiltration.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to bring systems to the patched versions listed above.

Proactive Monitoring: Monitor system logs for unexpected privilege escalation events, abnormal process execution, or failures related to the Projected File System driver.

Compensating Controls: Ensure that user account controls are strictly enforced and limit the number of users with local interactive access to critical systems to minimize the potential attack surface.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the official Microsoft security patches to all affected Windows endpoints. Because this vulnerability facilitates local privilege escalation, it is essential to patch promptly to prevent low privilege users from achieving full system control. Regular vulnerability scanning should be conducted to ensure all systems are updated to the specified non-vulnerable versions.

More Microsoft CVEs

Sources