Junglewise Threat Intelligence

CVE-2026-20934: Microsoft Windows SMB Server race condition privilege escalation

CVE-2026-20934 · Severity: high · CVSS 7.5 · Published 2026-01-13

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows SMB Server, which is the component responsible for file and printer sharing across a network. An authorized user with low-level access could exploit a timing flaw to gain higher-level administrative privileges on the system. This could allow an attacker to bypass security restrictions, access sensitive data, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows SMB Server due to improper synchronization during concurrent execution using a shared resource. An attacker must first be authenticated to the network with at least low-level privileges (PR:L). By exploiting this flaw through a network-based attack vector, the attacker can achieve local privilege escalation (LPE) to gain higher system rights. The attack complexity is considered high (AC:H) because it requires specific timing conditions to successfully trigger the race condition. Microsoft has released security updates to address this vulnerability across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
  • Microsoft Windows Server 2012 All versions

Timeline

  • 2026-01-13: disclosed
  • 2026-01-13: advisory

References

Related threats