Race Condition Vulnerability in .NET Framework by Microsoft
CVE-2026-23666

7.5HIGH

What is CVE-2026-23666?

A race condition vulnerability within the .NET Framework permits unauthorized attackers to exploit improper synchronization of shared resources, potentially leading to denial of service over networked systems. This vulnerability emphasizes the importance of implementing robust synchronization mechanisms to prevent concurrent execution issues that may degrade service availability.

Affected Version(s)

Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1809 for 32-bit Systems 4.7.0 < 2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0

Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0

Microsoft .NET Framework 3.5 AND 4.8.1 Windows 10 Version 21H2 for 32-bit Systems 4.8.1 < 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.