CVE-2026-25167
vulnerability analysis and mitigation

Overview

CVE-2026-25167 is a use-after-free (UAF) vulnerability in the Microsoft Brokering File System that allows an unauthorized local attacker to elevate privileges. It affects Windows 11 versions 24H2, 25H2, 26H1, and Windows Server 2025. The vulnerability was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday security update release. It carries a CVSS v3.1 base score of 7.4 (High) (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring within the Microsoft Brokering File System component. A use-after-free condition arises when memory that has been freed is subsequently accessed, potentially allowing an attacker to control the contents of that memory and redirect execution flow. The attack vector is local with high attack complexity, requires no privileges, and no user interaction, meaning a local attacker must craft specific conditions to trigger the memory corruption and achieve privilege escalation (Microsoft MSRC). No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation allows an unauthorized local attacker to escalate privileges to SYSTEM level on the affected Windows system, resulting in high impacts to confidentiality, integrity, and availability. An attacker who gains SYSTEM-level access can read sensitive data, modify system configurations, install malware, create backdoors, and potentially pivot to other systems on the network. The scope is limited to the affected host, but the privilege escalation capability makes this vulnerability a significant risk in multi-user or shared environments (Microsoft MSRC).

Mitigation and workarounds

Microsoft released security updates on March 10, 2026 to address this vulnerability. Affected systems should be updated to the following minimum build versions: Windows 11 24H2 (10.0.26100.7979 or later), Windows 11 25H2 (10.0.26200.7979 or later), Windows 11 26H1 (10.0.28000.1719 or later), and Windows Server 2025 (10.0.26100.32463 or later). No configuration-based workarounds have been published; applying the security update is the recommended and only confirmed remediation (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Zero Day Initiative, Sophos, and CyberSecurityNews, though CVE-2026-25167 itself did not receive significant individual attention given the absence of active exploitation (Zero Day Initiative, Rapid7, Sophos). Community sentiment reflected routine patch prioritization, with no notable alarm raised specifically around this CVE.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management