Junglewise Threat Intelligence

CVE-2026-58527: Microsoft Windows Runtime privilege escalation via race condition

CVE-2026-58527 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 25H2, Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2025, Microsoft Windows Server 2022, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows Runtime, a core component of the Windows operating system used for running modern applications. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A race condition (CWE-362) exists in the Windows Runtime due to improper synchronization during concurrent execution using a shared resource. The vulnerability is exploitable by a locally authenticated attacker with low privileges. By successfully winning the race condition, the attacker can achieve local privilege escalation (LPE), gaining SYSTEM-level access or equivalent high-level permissions. The flaw affects multiple versions of Windows 11 and Windows Server, and Microsoft has released security updates to address the issue.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26100.8875
  • Microsoft Windows 11 version 26H1 10.0.28000.0 to 10.0.28000.2525
  • Microsoft Windows Server 2022 10.0.20348.0 to 10.0.20348.5386
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates released for affected Windows versions.

References

Related threats