CVE-2026-32078 — Windows Projected File System Elevation of Privilege Vulnerability
Executive Summary
Use after free in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1809 for 32-bit Systems | 5082123 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5082123 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5082200 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5082052 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5082052 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems | 5083769 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for x64-based Systems | 5083769 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 25H2 for ARM64-based Systems | 5083769 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 25H2 for x64-based Systems | 5083769 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 26H1 for ARM64-based Systems | 5083768 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5083768 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5082123 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5082123 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 | 5082142 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022 (Server Core installation) | 5082142 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5082060 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2025 | 5082063 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2025 (Server Core installation) | 5082063 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5082123 |
Security Update | Yes |
5082200 |
Security Update | Yes |
5082052 |
Security Update | Yes |
5083769 |
Security Update | Yes |
5083768 |
Security Update | Yes |
5082142 |
Security Update | Yes |
5082060 |
Security Update | Yes |
5082063 |
Security Update | Yes |
Patch Diff
Reference-count underflow use-after-free (CWE-416) via cleanup asymmetry in the Windows Projected File System minifilter prjflt.sys PrjfScheduleExpansionWorkItem, local EoP. The function allocates a generic work item (FltAllocateGenericWorkItem), then ObfReferenceObject(FileObject) +1, then FltQueueGenericWorkItem. Two failure paths shared one cleanup block (LABEL_10/LABEL_14) that unconditionally ObfDereferenceObject(FileObject)'d: on queue-insert failure the ref was already taken (symmetric), but on ALLOCATION failure the goto reaches the same cleanup before ObfReferenceObject ran -> a dereference of a FILE_OBJECT never referenced here, so its refcount ends 1 lower than actual. Forcing FltAllocateGenericWorkItem to fail (pool pressure) drives the count to 0 while other paths hold the object -> free -> kernel UAF (reporter PoC reaches it via NtCreateFile on a ProjFS root: PrjfPostCreate -> PrjfProcessOpenWithinVirtualizationRoots -> PrjfExpandAndWait -> PrjfLaunchExpansion -> PrjfScheduleExpansionWorkItem). Diff of prjflt.sys 10.0.26100.8115 -> .8246 (Apr 14 2026, KB5083769) confirms the fix: gated behind CFR flag Feature_2428439865, a bool flag (init false) is set true only after ObfReferenceObject, and the shared-cleanup ObfDereferenceObject is guarded by `!feature || flag`. This is the ProjFS twin of the wcifs.sys cleanup-asymmetry bug CVE-2026-33098. Note: our diff shows Feature_2428439865 (build/arch).
| Function | Address | Change | Note |
|---|---|---|---|
PrjfScheduleExpansionWorkItem |
code change |
code (ref-tracking flag guards shared-cleanup deref, CFR-gated) | Pre: alloc-fail -> goto shared cleanup (LABEL_10/14) -> unconditional ObfDereferenceObject(FileObject) with no matching ObfReferenceObject -> refcount underflow -> UAF. Post (Feature_2428439865): bVar13=false, set true right after ObfReferenceObject; cleanup does ObfDereferenceObject only if `!feature || bVar13`. |
Feature_2428439865 |
gate |
added (CFR gate) | CFR flag gating the guarded dereference; original unconditional deref still ships when disabled. |
Attack Path
An allocation-failure path dereferences a FILE_OBJECT it never referenced, underflowing the refcount to a free-while-in-use
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Known Exploits
Acknowledgments
ChenJian with Sea Security Orca Team