Executive brief
A security vulnerability exists in the Windows Server Message Block (SMB) protocol, which is used for sharing files and printers across a network. An authorized user on the network could exploit a timing-related flaw to gain higher-level system permissions than they should have. This could allow an attacker to access restricted data or perform unauthorized administrative actions on affected Windows systems.
Technical details
A race condition (CWE-362) and subsequent use-after-free (CWE-416) vulnerability exists in the Windows SMB implementation. The flaw is triggered by improper synchronization during concurrent execution using shared resources. An attacker with low-privileged network access can exploit this timing issue to achieve elevated privileges on the target system. The attack requires a high level of complexity to successfully win the race condition, but it can be executed remotely over the network without user interaction. Microsoft has released security updates to address this issue across various Windows and Windows Server versions.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard and Server Core
Timeline
- 2026-07-14: disclosed: Vulnerability published by Microsoft and NVD.
- 2026-07-14: advisory: Microsoft Security Update Guide published.