Junglewise Threat Intelligence

CVE-2026-34334: Microsoft Windows race condition in TCP/IP

CVE-2026-34334 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows TCP/IP component, which handles network communications for the operating system. An attacker who already has basic access to a computer could exploit a timing error to gain full administrative control. This could allow them to steal sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists within the Windows TCP/IP stack due to improper synchronization when accessing shared resources. An attacker with local access and low-level privileges can exploit this flaw by carefully timing execution threads to manipulate shared memory or system states. Successful exploitation allows the attacker to gain elevated privileges, potentially reaching SYSTEM level. The vulnerability is triggered locally without requiring user interaction, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows Not specified (Windows TCP/IP stack)

Timeline

  • 2026-05-12: disclosed: Initial publication by Microsoft and NVD
  • 2026-05-12: advisory: Microsoft Security Update Guide published

References

Related threats