CVE-2026-69466
massTOCTOU Race Condition in Windows Kernel Enables Local Privilege Escalation
CVE-2026-69466 is a time-of-check time-of-use (TOCTOU) race condition (CWE-367) in the Windows Kernel, assigned by Microsoft. To trigger it, an attacker who can already run low-privileged code on the local machine must win a timing race between a security check and the kernel's later use of the same resource, a high-complexity condition that makes reliable exploitation difficult. A successful race lets the attacker elevate privileges beyond the standard user context they started with, with high impact on confidentiality, integrity, and availability on the local system. All Windows systems carrying the affected kernel code are potentially exposed, though the available data does not specify which Windows versions or builds are impacted. There is currently no evidence of exploitation in the wild, no public proof-of-concept, and a low EPSS probability of 0.2% within the next 30 days.
What to do: Apply Microsoft's security update for this CVE as soon as it is released, and check Microsoft's advisory for the exact affected Windows builds or KB updates, since version ranges are not listed in the available data. Until patched, reduce risk by limiting which users can execute code on shared or multi-user Windows systems. Monitor Microsoft advisories and exploit feeds for emerging proof-of-concept code, given the kernel-level impact.
| Microsoft Windows Kernel | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Time-of-check time-of-use (toctou) race condition in Windows Kernel allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.