CVE-2026-20921

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

high 7.5 CVSS 3.1
Published: Jan 13, 2026
Modified: May 26, 2026
Vendor: Microsoft
Product: Windows 10 1607
Versions: r2

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB Server allows an authorized attacker to elevate privileges over a network.

References

Related CVEs