Junglewise Threat Intelligence

CVE-2026-42900: Microsoft Windows App Store race condition privilege escalation

CVE-2026-42900 · Severity: high · CVSS 8.1 · Published 2026-07-14

Technologies: Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows App Store, the central platform used for downloading and updating applications on Windows devices. An attacker could exploit this flaw to gain elevated system permissions, potentially allowing them to take control of the affected computer or access restricted data. This issue is particularly significant as it can be triggered over a network without requiring any interaction from the user.

Technical details

A race condition (CWE-362) exists in the Windows App Store component of Microsoft Windows, which can lead to a use-after-free (CWE-416) scenario. The vulnerability is exploitable over the network without prior authentication or user interaction, though it requires the attacker to win a timing-based race condition (High Attack Complexity). Successful exploitation allows an attacker to elevate their privileges on the target system, potentially achieving full system compromise. Microsoft has released security updates for affected versions of Windows 10, Windows 11, and Windows Server 2016 to address this synchronization issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2016 All versions including Server Core

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD

References

Related threats