Junglewise Threat Intelligence

CVE-2026-20919: Microsoft Windows SMB Server race condition privilege escalation

CVE-2026-20919 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows SMB Server, which is the component responsible for sharing files and printers across a network. An authorized user on the network could exploit a timing flaw to gain higher-level administrative permissions than they should have. This could allow an attacker to access sensitive data, modify system settings, or disrupt operations across the corporate network.

Technical details

A race condition vulnerability (CWE-362) exists in the Windows SMB Server due to improper synchronization when handling concurrent executions using shared resources. An attacker must be authenticated to the network with at least low-level privileges to attempt an exploit. By successfully winning the race condition over the network, the attacker can achieve elevated privileges on the target system. The vulnerability affects a wide range of Windows client and server versions, including Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue by improving resource synchronization within the SMB server component.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats