Race Condition in .NET Framework Leads to Denial of Service
CVE-2026-32226

5.9MEDIUM

What is CVE-2026-32226?

A race condition vulnerability in the .NET Framework allows an unauthorized attacker to exploit shared resources through improper synchronization. This can result in denial of service, making network services unavailable to legitimate users. Organizations using affected versions are urged to implement patches and updates to safeguard their applications from potential disruptions.

Affected Version(s)

Microsoft .NET Framework 3.5 AND 4.7.2 Windows 10 Version 1809 for ARM64-based Systems 4.7.0 < 2.0.50727.9068 & 3.0.30729.9065 & 4.7.4141.0

Microsoft .NET Framework 3.5 AND 4.8 Windows 10 Version 1809 for 32-bit Systems 4.8.0 < 2.0.50727.9068 & 3.0.30729.9065 & 4.8.4801.0

Microsoft .NET Framework 3.5 AND 4.8.1 Windows 11 Version 26H1 for ARM64-based Systems 4.8.1 < 2.0.50727.9181 & 3.0.30729.9165 & 4.8.9332.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.