Junglewise Threat Intelligence

CVE-2026-20853: Microsoft Windows race condition in WalletService

CVE-2026-20853 · Severity: high · CVSS 7.4 · Published 2026-01-13

Technologies: Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows WalletService, a component responsible for managing digital payment and loyalty cards. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could lead to the theft of sensitive data, installation of malicious software, or disruption of business operations.

Technical details

A race condition (CWE-362) exists in the Windows WalletService due to improper synchronization when accessing shared resources. The vulnerability is triggered locally and has a high attack complexity, as it requires the attacker to successfully time the exploit to win the race condition. If successful, an unauthorized attacker can elevate their privileges, potentially gaining SYSTEM-level access. Microsoft has released security updates to address this issue across multiple versions of Windows 10 and Windows 11.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats