Windows SMB Elevation of Privilege Vulnerability

Plan PatchCVSS 7.5CVE-2026-58531Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionNone needed
Summary

A race condition in Windows SMB allows an authorized attacker to elevate privileges over a network through concurrent execution using a shared resource with improper synchronization.

What this means
What could happen
An attacker with low-level user credentials on your network could gain elevated privileges on Windows servers or workstations, potentially allowing them to access sensitive data, modify system configurations, or deploy malware across your infrastructure.
Who's at risk
IT managers running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should prioritize this. The vulnerability affects all versions and architectures of these systems that have network-facing SMB enabled, which includes any server providing file sharing, print services, or remote access capabilities typical in municipal utilities and water authorities.
How it could be exploited
An attacker with valid user credentials on your network initiates concurrent SMB requests to exploit a race condition in the shared resource handling. By timing these requests carefully, they can bypass privilege checks and gain system-level access without requiring administrative credentials.
Prerequisites
  • Valid user account credentials on the network
  • Network access to SMB-enabled Windows systems (port 445)
  • Ability to execute concurrent SMB requests
remotely exploitablelow complexityhigh CVSS score (7.5)requires valid credentials but low-privilege account sufficientexploitation more likely
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/11
Do now
0/1
WORKAROUNDRestrict network access to SMB ports (445/TCP and 139/TCP) at the firewall to only authorized systems and networks
Schedule — requires maintenance window
0/9

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 and 2019 (Server Core) to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 and 2025 (Server Core) to Build 10.0.26100.33158 or later
Windows Server 2016
HOTFIXUpdate Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 to Build 10.0.14393.9339 or later
All products
HOTFIXUpdate Windows 10 Version 1809 32-bit and x64 systems to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 (32-bit, ARM64, x64) to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 (32-bit, ARM64, x64) to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 and 25H2 (ARM64 and x64) to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 26H1 (ARM64 and x64) to Build 10.0.28000.2525 or later
Long-term hardening
0/1
HARDENINGReview and enforce strong password policies to limit risk from low-privilege account compromise
API: /api/v1/advisories/99164759-bcaa-47af-9b6f-cdad42dbf9b1

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Windows SMB Elevation of Privilege Vulnerability | CVSS 7.5 - OTPulse