Junglewise Threat Intelligence

CVE-2026-20848: Microsoft Windows SMB Server race condition privilege escalation

CVE-2026-20848 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows SMB Server, which is the component responsible for sharing files and printers over a network. An authorized user on the network could exploit a timing-related flaw to gain higher-level system permissions than they should have. This could allow an attacker to access restricted data or perform unauthorized administrative actions across the corporate network.

Technical details

A race condition vulnerability (CWE-362) exists in the Windows SMB Server due to improper synchronization when multiple processes or threads access a shared resource. An attacker must be authenticated to the network with at least low-level privileges to attempt an exploit. By successfully winning the race condition over the network, the attacker can achieve elevation of privilege, potentially gaining full control over the affected system. Microsoft has released security updates to address this issue across various versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats