Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisorycredential-access-method

Microsoft Patches Multiple Windows Use-After-Free Privilege Escalation Flaws

Updated 28d agoFirst seen May 25, 202611 sources

Microsoft released fixes for several Windows elevation-of-privilege vulnerabilities affecting Win32k, Windows Telephony Service, Desktop Window Manager, and the Windows Cloud Files Mini Filter Driver. The disclosed flaws include CVE-2026-34347, CVE-2026-42825, CVE-2026-27923, and CVE-2026-35418, and are all tied to use-after-free conditions, with some cases also involving race conditions such as time-of-check time-of-use behavior. Microsoft said successful exploitation could let a locally authenticated attacker with low privileges gain SYSTEM access without user interaction.

The vulnerabilities were rated Important with CVSS 3.1 scores ranging from 7.0 to 7.8, and Microsoft assessed exploitation as less likely or unlikely because several attacks require winning a race condition. At the time of disclosure, Microsoft reported no public disclosure and no evidence of active exploitation for the documented 2026 flaws, and stated that official security updates were available. Additional Microsoft advisories also reference related Windows and Microsoft Brokering File System elevation-of-privilege issues, including CVE-2026-24285, CVE-2025-32712, CVE-2025-21372, CVE-2025-21315, and CVE-2025-59189, though public technical details for those entries were limited.

Share:
Microsoft Patches Multiple Windows Use-After-Free Privilege Escalation Flaws
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
May 12, 20261mo ago

Microsoft discloses CVE-2026-42825 Telephony Service flaw

Microsoft disclosed CVE-2026-42825, an Important Windows Telephony Service elevation-of-privilege vulnerability caused by a use-after-free flaw. The advisory states exploitation would require winning a race condition to obtain SYSTEM privileges, with no public disclosure or in-the-wild exploitation reported and an official fix released.

Microsoft discloses CVE-2026-35418 Cloud Files Mini Filter Driver flaw

Microsoft disclosed CVE-2026-35418, an Important elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver involving a use-after-free and TOCTOU race condition. Microsoft said the flaw could let a locally authorized low-privilege attacker elevate to SYSTEM, was not publicly disclosed or exploited in the wild, and was fixed at publication.

Microsoft discloses CVE-2026-34337 Cloud Files Mini Filter Driver flaw

Microsoft disclosed CVE-2026-34337, an Important elevation-of-privilege vulnerability in the Windows Cloud Files Mini Filter Driver caused by a use-after-free condition and race condition weakness. The advisory said a locally authenticated low-privilege attacker could elevate to SYSTEM without user interaction, with no public disclosure or active exploitation reported and an official fix available at publication.

CVE-2026-34337 - Security Update Guide - Microsoft - Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

Microsoft discloses CVE-2026-34347 Win32k-GRFX flaw

Microsoft disclosed CVE-2026-34347, an Important Windows Win32k elevation-of-privilege vulnerability caused by a use-after-free flaw in Win32K-GRFX. The company said a locally authenticated low-privilege attacker could potentially gain SYSTEM privileges by winning a race condition, with no public disclosure or active exploitation reported and a fix available.

Apr 14, 20262mo ago

Microsoft discloses CVE-2026-27924 Desktop Window Manager flaw

Microsoft published a Security Update Guide entry for CVE-2026-27924, a Desktop Window Manager elevation-of-privilege vulnerability. Although no synopsis is provided in the reference, the publication indicates formal disclosure through Microsoft's advisory process with a security update available.

CVE-2026-27924 - Security Update Guide - Microsoft - Desktop Window Manager Elevation of Privilege Vulnerability

Microsoft discloses CVE-2026-27923 Desktop Window Manager flaw

Microsoft disclosed CVE-2026-27923, an Important Desktop Window Manager elevation-of-privilege vulnerability caused by a use-after-free weakness. The company said exploitation was not publicly disclosed or observed in the wild, assessed exploitation as less likely, and released an official fix.

Mar 10, 20264mo ago

Microsoft discloses CVE-2026-24285 Win32k EoP flaw

Microsoft added CVE-2026-24285 to the Security Update Guide as a Win32k elevation-of-privilege vulnerability. Although no synopsis is provided in the reference, the publication indicates formal disclosure and patch availability through Microsoft's update process.

Oct 14, 20258mo ago

Microsoft discloses CVE-2025-59189 and releases a fix

Microsoft published advisory information for CVE-2025-59189, a Microsoft Brokering File System elevation-of-privilege vulnerability. The Security Update Guide entry indicates disclosure and patch availability on the publication date.

Jun 10, 20251y ago

Microsoft discloses CVE-2025-32712 Win32k EoP flaw

Microsoft published a Security Update Guide entry for CVE-2025-32712, a Win32k elevation-of-privilege vulnerability. While the reference provides no synopsis, the publication reflects formal disclosure through Microsoft's advisory process with a security update release.

Jan 14, 20251y ago

Microsoft discloses CVE-2025-21372 and releases a fix

Microsoft published advisory information for CVE-2025-21372, another Microsoft Brokering File System elevation-of-privilege vulnerability. The Security Update Guide entry shows the issue was disclosed with a corresponding fix available on the publication date.

Microsoft discloses CVE-2025-21315 and releases a fix

On Patch Tuesday, Microsoft published guidance for CVE-2025-21315, a Microsoft Brokering File System elevation-of-privilege vulnerability. The reference indicates an official security update was made available at publication.

SOURCE COVERAGE

Sources

11 references tracked. Mallory keeps watching after this page renders.

11 SOURCESView all
Msrc MicrosoftAdvisories
May 12, 2026

CVE-2026-42825 - Security Update Guide - Microsoft - Windows Telephony Service Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
May 12, 2026

CVE-2026-35418 - Security Update Guide - Microsoft - Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
May 12, 2026

CVE-2026-34347 - Security Update Guide - Microsoft - Windows Win32k Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
May 12, 2026

CVE-2026-34337 - Security Update Guide - Microsoft - Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
3 additional sources from 10-03-2026 to 14-04-2026
Msrc MicrosoftAdvisories
Oct 14, 2025

CVE-2025-59189 - Security Update Guide - Microsoft - Microsoft Brokering File System Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc Product AdvisoriesAdvisories
Jun 10, 2025

CVE-2025-32712 - Security Update Guide - Microsoft - Win32k Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Jan 14, 2025

CVE-2025-21315 - Security Update Guide - Microsoft - Microsoft Brokering File System Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
Msrc MicrosoftAdvisories
Jan 14, 2025

CVE-2025-21372 - Security Update Guide - Microsoft - Microsoft Brokering File System Elevation of Privilege Vulnerability

msrc.microsoft.com

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches Multiple Windows Use-After-Free Privilege Escalation Flaws | Mallory