Junglewise Threat Intelligence

CVE-2026-34351: Microsoft Windows TCP/IP race condition privilege escalation

CVE-2026-34351 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Microsoft Windows, Microsoft Windows 10, Microsoft Windows Server, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows networking component (TCP/IP) that could allow a user with basic access to a computer to gain full administrative control. By exploiting a timing flaw in how the system handles network data, an attacker can bypass security restrictions to run malicious code with high-level system privileges. This could lead to a complete takeover of the affected machine, allowing the attacker to access sensitive data or disrupt operations.

Technical details

A race condition vulnerability (CWE-362) exists within the Windows TCP/IP driver due to improper synchronization when accessing shared resources. An attacker with low-privileged local access can exploit this flaw by carefully timing execution threads to manipulate shared memory or state before the system can properly validate or lock it. Successful exploitation allows the attacker to execute arbitrary code in the context of the SYSTEM account, leading to full local privilege escalation (LPE). The vulnerability is reachable locally without user interaction, and Microsoft has released security updates to address the synchronization logic.

Affected products

  • Microsoft Windows All supported versions including Windows 10, 11, and Server

Timeline

  • 2026-05-12: disclosed: Initial disclosure by Microsoft and NVD
  • 2026-05-12: advisory: Microsoft Security Response Center published the update guide

References

Related threats