Microsoft disclosed two Elevation of Privilege vulnerabilities in the Microsoft Brokering File System, tracked as CVE-2025-49693 and CVE-2026-32219, through its Security Update Guide. Both advisories identify the same Windows component as affected, indicating a recurring privilege-escalation risk in the brokering layer that manages file system operations.
The vulnerabilities could allow an attacker with local access to gain higher privileges on a targeted Windows system if successfully exploited. Microsoft published security updates for both issues and organizations using affected Windows platforms should prioritize patching, validate update deployment across endpoints and servers, and monitor for signs of post-compromise privilege escalation involving the Brokering File System component.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft added CVE-2026-32219, another Microsoft Brokering File System Elevation of Privilege vulnerability, to its Security Update Guide.
Microsoft added CVE-2025-49693, a Microsoft Brokering File System Elevation of Privilege vulnerability, to its Security Update Guide.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.