Executive brief
A security vulnerability exists in the Windows SMB Server, which is the component responsible for file and printer sharing across a network. An authorized user with low-level access could exploit a timing flaw to gain higher-level administrative privileges. This could allow an attacker to take full control of affected servers or workstations, potentially leading to data theft or service disruption.
Technical details
A race condition (CWE-362) exists in the Windows SMB Server due to improper synchronization during concurrent execution using shared resources. The vulnerability is reachable over the network but requires the attacker to have at least low-level authenticated access (PR:L) and involves high attack complexity (AC:H) due to the timing requirements of a race condition. Successful exploitation allows for a local privilege escalation, granting the attacker high confidentiality, integrity, and availability impacts. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.
Affected products
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows Server 2012 R2
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2
- Microsoft Windows Server 2016 All versions
- Microsoft Windows Server 2019 All versions
- Microsoft Windows Server 2022 All versions, 23H2
- Microsoft Windows Server 2025 All versions
Timeline
- 2026-01-13: disclosed: Initial disclosure by Microsoft
- 2026-01-13: advisory: NVD entry published
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20921
- https://www.vicarius.io/vsociety/posts/cve-2026-20921-detection-script-race-condition-vulnerability-in-windows-smb-server
- https://www.vicarius.io/vsociety/posts/cve-2026-20921-remediation-script-race-condition-vulnerability-in-windows-smb-server