Microsoft: Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability

Microsoft: Windows 11 and Server 2025 Exposed to High-Severity Brokering File System Vulnerability

High-Severity Windows 11 & Server 2025 Vulnerability Exploits Brokering File System Flaw

A critical local privilege escalation vulnerability, tracked as CVE-2026-50458 (CVSS 7.8), has been identified in Microsoft’s Brokering File System (BFS), affecting Windows 11 (versions 24H2, 25H2, and 26H1) and Windows Server 2025, including Server Core installations. The flaw, disclosed by security researcher Rotce, stems from a use-after-free condition caused by a race condition in BFS’s directory handling, allowing attackers to corrupt kernel memory and gain SYSTEM-level privileges.

BFS, a minifilter driver, manages file, pipe, and registry access for sandboxed applications (e.g., AppContainer and UWP apps), enforcing isolation between these environments and the OS. Exploitation of this vulnerability bypasses sandbox protections, enabling attackers to escalate from a low-privileged or sandboxed context to full system control. Successful exploitation requires local authenticated access, with attackers leveraging crafted IOCTL requests to manipulate the vulnerable path and trigger memory corruption.

Affected Systems & Patch Status
The vulnerability impacts:

  • Windows 11 24H2 (builds < 26100.8875)
  • Windows 11 25H2 (builds < 26200.8875)
  • Windows 11 26H1 (builds < 28000.2269)
  • Windows Server 2025 (builds < 26100.33158)

Microsoft addressed the flaw in the July 14, 2026 Patch Tuesday update (KB5101650), with cumulative updates for all affected versions. As of now, no active exploitation has been reported, and the vulnerability is not listed on CISA’s Known Exploited Vulnerabilities Catalog. However, its kernel-level impact and the widespread use of Windows 11 and Server 2025 in enterprise environments heighten the risk of potential abuse.

Security teams are advised to verify system builds against the vulnerable ranges and prioritize patching to mitigate exposure.

Source: https://cybersecuritynews.com/windows-brokering-file-system-vulnerability/

Microsoft cybersecurity rating report: https://www.rankiteo.com/company/microsoft

"id": "MIC1784816949",
"linkid": "microsoft",
"type": "Vulnerability",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Users of Windows 11 (24H2, '
                                              '25H2, 26H1) and Windows Server '
                                              '2025',
                        'industry': 'Software',
                        'location': 'Global',
                        'name': 'Microsoft',
                        'size': 'Enterprise',
                        'type': 'Technology Vendor'}],
 'attack_vector': 'Local',
 'date_publicly_disclosed': '2026-07-14',
 'date_resolved': '2026-07-14',
 'description': 'A critical local privilege escalation vulnerability, tracked '
                'as CVE-2026-50458 (CVSS 7.8), has been identified in '
                'Microsoft’s Brokering File System (BFS), affecting Windows 11 '
                '(versions 24H2, 25H2, and 26H1) and Windows Server 2025, '
                'including Server Core installations. The flaw stems from a '
                'use-after-free condition caused by a race condition in BFS’s '
                'directory handling, allowing attackers to corrupt kernel '
                'memory and gain SYSTEM-level privileges. Exploitation '
                'bypasses sandbox protections, enabling attackers to escalate '
                'from a low-privileged or sandboxed context to full system '
                'control.',
 'impact': {'operational_impact': 'Potential full system compromise, bypass of '
                                  'sandbox protections',
            'systems_affected': 'Windows 11 (24H2, 25H2, 26H1), Windows Server '
                                '2025 (including Server Core)'},
 'investigation_status': 'Patched; no active exploitation reported',
 'post_incident_analysis': {'corrective_actions': 'Patch released to address '
                                                  'memory corruption '
                                                  'vulnerability',
                            'root_causes': 'Use-after-free condition in '
                                           'Brokering File System (BFS) due to '
                                           'race condition in directory '
                                           'handling'},
 'recommendations': 'Verify system builds against vulnerable ranges and '
                    'prioritize patching (KB5101650).',
 'references': [{'source': 'Microsoft Security Update Guide'},
                {'source': 'Researcher Rotce'}],
 'response': {'containment_measures': 'Patch released (KB5101650)',
              'remediation_measures': 'Apply July 14, 2026 Patch Tuesday '
                                      'update (KB5101650)'},
 'title': 'High-Severity Windows 11 & Server 2025 Vulnerability Exploits '
          'Brokering File System Flaw',
 'type': 'Local Privilege Escalation',
 'vulnerability_exploited': 'CVE-2026-50458 (Use-after-free in Brokering File '
                            'System)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.