Race Condition Vulnerability in Windows Kerberos Security Feature
CVE-2026-24297

6.5MEDIUM

What is CVE-2026-24297?

A race condition vulnerability exists in Windows Kerberos due to improper synchronization of shared resources. This flaw may allow unauthorized users to bypass critical security measures over a network, potentially compromising the integrity of the system. Organizations using affected Windows Kerberos implementations should prioritize patching to mitigate the risks associated with this vulnerability.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8957

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8511

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7058

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.