Race Condition Vulnerability in Microsoft Windows Network File System
CVE-2026-56649

5.9MEDIUM

What is CVE-2026-56649?

A vulnerability exists in the Windows Network File System that allows unauthorized execution of code when concurrent execution occurs due to improper synchronization (race condition). Attackers exploiting this flaw could gain control over affected systems through network connections, potentially leading to significant security breaches.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9339

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.