Race Condition Vulnerability in Windows SMB Server by Microsoft
CVE-2026-20927

5.3MEDIUM

What is CVE-2026-20927?

A race condition vulnerability in Windows SMB Server results from improper synchronization during concurrent execution with shared resources. This flaw can be exploited by an authorized attacker to create a denial of service condition over a network, impacting accessibility and performance for legitimate users. Organizations using affected Windows SMB Server versions should take immediate action to apply patches and safeguard their systems.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8783

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8276

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6809

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.