Race Condition Vulnerability in Windows Connected Devices Platform Service by Microsoft
CVE-2026-21234
7HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 10 February 2026
What is CVE-2026-21234?
A privilege escalation vulnerability exists in the Windows Connected Devices Platform Service due to improper synchronization when accessing shared resources. An attacker with local access can exploit this flaw to execute concurrent processes in a manner that allows them to elevate their privileges, potentially leading to unauthorized actions on the affected system. Ensuring timely updates and patches is essential to safeguard against such vulnerabilities.
Affected Version(s)
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8389
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6937
Windows 10 Version 22H2 32-bit Systems 10.0.19045.0 < 10.0.19045.6937