Executive brief
A race condition vulnerability exists in the Microsoft .NET Framework, a software framework used by many Windows applications. An unauthorized attacker could exploit this flaw over a network to cause a denial-of-service condition, potentially making affected applications or services unavailable to users. This impact is limited to service availability and does not involve the theft of customer data.
Technical details
A race condition (CWE-362) exists in Microsoft .NET Framework due to improper synchronization when multiple threads access a shared resource. The vulnerability is reachable over the network and does not require user interaction or administrative privileges, though the attack complexity is rated as high. Successful exploitation allows an attacker to trigger a denial-of-service (DoS) state. Affected versions include .NET Framework 3.5, 4.7.2, 4.8, and 4.8.1 across various Windows and Windows Server platforms. Security updates are available via the Microsoft Security Response Center (MSRC).
Affected products
- Microsoft .NET Framework 3.5, 4.7.2, 4.8, 4.8.1
Timeline
- 2026-04-14: disclosed
- 2026-04-14: advisory