Executive brief
A security vulnerability has been identified in the networking component of Microsoft Windows that could allow an attacker to take control of a computer. To exploit this, an attacker must be on the same local network (such as the same Wi-Fi or office network) as the target device. If successful, the attacker could execute malicious code, potentially leading to data theft or full system compromise.
Technical details
This vulnerability is classified as a race condition (CWE-362) within the Windows TCP/IP stack, occurring due to improper synchronization during concurrent execution using shared resources. An unauthenticated attacker can exploit this flaw by sending specially crafted network traffic over an adjacent network (Layer 2 reachability). Successful exploitation allows for remote code execution in the context of the kernel. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 All editions
Timeline
- 2026-07-14: advisory: Initial disclosure by Microsoft and NVD