Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Microsoft Brokering File System Vulnerability Enables Local Privilege Escalation

Microsoft has addressed a critical use-after-free vulnerability in its Brokering File System (BFS) driver, identified as CVE-2025-29970, which could allow attackers to escalate privileges on Windows systems. This security flaw affects the bfs.sys…

Microsoft has addressed a critical use-after-free vulnerability in its Brokering File System (BFS) driver, identified as CVE-2025-29970, which could allow attackers to escalate privileges on Windows systems. This security flaw affects the bfs.sys component and was discovered by researchers at HT3Labs.

The Brokering File System, introduced alongside Windows' Win32 App Isolation feature approximately two years ago, is a mini-filter driver that manages I/O operations for isolated applications. BFS specifically handles file access from sandboxed applications, making it a critical security boundary. The vulnerability arises from improper memory management during the cleanup of policy entries within the driver.

The flaw lies in the BfsCloseStorage function, where the DirectoryBlockList linked list is deallocated incorrectly. During cleanup, the head of the linked list is freed at the end of the first iteration, but the function continues to dereference this freed memory in subsequent iterations when processing additional entries. This creates a use-after-free condition that can lead to system crashes or potentially privilege escalation.

This security flaw affects the bfs.sys component and was discovered by researchers at HT3Labs.
Derek Vaughn · Thehackingpost

The vulnerability occurs during the StorageObject cleanup phase, where the deallocation loop in BfsCloseStorage improperly handles the DirectoryBlockList structure. The function retrieves the first entry of the linked list, performs integrity checks, unlinks the node, deallocates the accompanying DirectoryBlockBuffer and the node itself, and then frees the list head all within a single iteration. This flawed logic means that when a linked list contains multiple entries, the head is deallocated prematurely, leading to subsequent iterations accessing freed memory.

The tight window between memory deallocation and reuse makes exploitation challenging. However, attackers with local access and appropriate tokens could trigger the vulnerability. To exploit CVE-2025-29970, attackers must satisfy several conditions. They need a handle containing a specific token that enables BFS IOCTL calls, typically obtained by impersonating a suitable process with an AppSilo token. PolicyEntry objects must exist in the PolicyTable at the time of the removal request, and these entries must have an attached StorageObject with a DirectoryBlockList containing multiple entries.

Advertisement

While CVE-2025-29970 poses challenges for exploitation due to limited pointer usage and a narrow window of opportunity, it highlights ongoing security concerns with Windows sandboxing mechanisms. As Microsoft expands application isolation features through AppContainer and AppSilo technologies, drivers like BFS represent increasingly attractive targets for privilege escalation attacks. Security researchers recommend that organizations apply the latest Windows security updates promptly to protect against this and similar vulnerabilities in the Brokering File System.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories