Privacy News What is the viral whesvc service and should you disable it

Parkinsond

Level 64
Thread author
Verified
Top Poster
Well-known
Dec 6, 2023
5,393
16,856
6,269
The week started turbulently as a viral post on X claimed Microsoft snuck a background service into Windows 11 that spies on you and tanks gaming performance. The claim managed to rack up enough controversy to force Microsoft’s own executive Scott Hanselman to jump in and correct the record.

The service in question is whesvc, or Windows Health and Optimized Experiences, and yes it does run in the background on every Windows 11 installation. But it’s far less controversial than it originally appeared.

To be fair, Microsoft does collect some data on you, but that’s all known, although not very well-documented, and you agree to it as soon as you install Microsoft products on your PC. The most recent example, which also caused mild controversy, was the GDID identifier. You can read more about it here.

Whesvc runs as a resident, privileged service, and it had an actual vulnerability tied to it, CVE-2025-59241. This is a high-severity local privilege escalation bug tied to how the service handles file paths. Now, Microsoft has since patched the vulnerability, so you probably don’t have to worry about it. But the security history is there.

 
Interesting read, thank you @Parkinsond

As far as the Should you actually disable whesvc part? (quick view) :)

.....Beyond that, the case for disabling it comes down to whether you want the functionality it provides. If you're on a desktop with no battery to manage and you never plan to submit a Feedback Hub sluggishness report, whesvc genuinely isn't doing much for you day to day.

But if you’re on a laptop, disabling whesvc also turns off Adaptive Energy Saver. So, if you’re using this feature, disabling the service comes with a real tradeoff.

For most people, the honest answer is that it's not worth the effort either way. Especially after we’ve established that it barely takes up any resources.
 
Last edited: