Executive brief
A security vulnerability exists in the Windows networking component (TCP/IP) that could allow a user with basic access to a computer to gain full administrative control. This component is responsible for how the computer communicates over a network. If exploited, an attacker could bypass security restrictions to access sensitive data, install software, or disrupt operations on the affected system.
Technical details
A race condition exists within the Windows TCP/IP driver due to improper synchronization when handling shared resources. While initially reported as a stack-based buffer overflow (CWE-121), the description was updated to reflect a concurrent execution flaw. An attacker with local access and low privileges can exploit this vulnerability to execute code with elevated permissions, potentially reaching SYSTEM level. The attack requires no user interaction. Microsoft has released security updates to address this issue across various versions of Windows 10, 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 23H2, 24H2, 25H2, 26H1
- Microsoft Windows Server 2016 All versions
- Microsoft Windows Server 2019 All versions
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory: Initial advisory published by Microsoft
- 2026-06-01: other: Vulnerability description updated from buffer overflow to race condition