CVE-2026-69385
massRace Condition in Microsoft Windows TCP/IP Enables Local Privilege Escalation
CVE-2026-69385 is a race condition (CWE-362) — improper synchronization when concurrently accessing a shared resource, with related use-after-free behavior (CWE-416) — in the Windows TCP/IP networking component. It is triggered when a local, authorized attacker runs operations that race on the shared TCP/IP resource; because the exploitable timing window is narrow (CVSS attack complexity: high), exploitation is timing-dependent and not trivially repeatable. A successful race lets the attacker elevate privileges locally, from a limited user account to higher (kernel/SYSTEM-level) rights, with high impact on the confidentiality, integrity, and availability of the host. Any Windows system carrying the affected TCP/IP stack is potentially affected; the available data does not specify exact Windows version ranges, so defenders should consult Microsoft's advisory for in-scope releases. There is currently no known exploitation: the flaw is not in CISA's KEV, no public proof-of-concept exists, and EPSS assigns only a 0.2% probability of exploitation within 30 days (11th percentile).
What to do: Apply Microsoft's security update for CVE-2026-69385 as soon as it is released, prioritizing multi-user hosts, servers with interactive logons, and machines where untrusted users hold local accounts, since exploitation requires local access and a difficult-to-hit timing window. Until patched, restrict local logon rights to trusted users. Check Microsoft's advisory for the exact affected Windows versions to confirm whether your systems are in scope.
| Microsoft Windows TCP/IP (Windows operating systems) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-362, CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.