Time-of-Check Time-of-Use Race Condition in Windows Network File System
CVE-2026-56648

7.5HIGH

What is CVE-2026-56648?

A vulnerability exists in the Windows Network File System where a time-of-check time-of-use (TOCTOU) race condition can allow an authorized attacker to exploit the issue and elevate privileges over a network. This flaw may grant attackers unauthorized access to sensitive operations, making it crucial for system administrators to apply available patches and mitigations promptly.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9339

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.