Microsoft describes the issue as concurrent execution using a shared resource with improper synchronization—a race condition—in Windows TCP/IP. An attacker must successfully win that race condition to exploit the flaw.
CVE-2026-69385 at a glance
- Title: Windows TCP/IP Elevation of Privilege Vulnerability
- Severity: Important
- CVSS base score: 7.0
- CVSS temporal score: 6.1
- CVSS vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C - CWE: CWE-362, CWE-416
- Exploitation assessment: Exploitation More Likely
- Publicly disclosed: No
- Exploited: No
- Customer action required: Yes
The CVSS vector classifies the attack as local (AV:L) and requires low privileges (PR:L), with no user interaction (UI:N). Microsoft’s advisory also specifies that successful exploitation requires high attack complexity because the attacker must win the race condition. The potential impact spans confidentiality, integrity, and availability.
What the vulnerability means
The flaw is located in Windows TCP/IP, the part of Windows responsible for network communication. It is an elevation-of-privilege vulnerability rather than a direct remote-code-execution issue: an attacker needs authorized access to the device first.
Microsoft’s advisory states: “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.” SYSTEM is a highly privileged Windows security context used by core operating-system services. An account operating at that level could potentially make security-sensitive changes, access protected resources, or interfere with system services.
The weakness is classified under:
- CWE-362 — Concurrent Execution using Shared Resource with Improper Synchronization
- CWE-416 — Use After Free
Race conditions are difficult to exploit reliably because success depends on timing. But “difficult” is not the same thing as “harmless,” particularly where an attacker already has a foothold on a workstation or server. Patch management remains the clean answer; timing bugs do not become less awkward because they are technically fussy.
Affected Windows products and fixed builds
Install the applicable Microsoft update and verify the device reaches the corresponding fixed build.
Windows 10
- For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
- For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
- For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
- For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
Windows 11
- For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
- For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
- For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
- For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
- For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
- For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
- For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
- For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
Windows Server
- For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
- For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
- For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
- For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
- For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
- For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
- For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
Practical action for administrators
Because Microsoft marks customer action as required, administrators should identify systems running the affected Windows client and server releases, deploy the applicable cumulative update, and validate the resulting OS build against the fixed-build values above.
For managed environments, the priority should include servers and shared workstations where a lower-privileged user, service account, or already-compromised account could provide the local access needed to attempt elevation. The vulnerability’s high complexity should inform risk assessment, not delay patch deployment. SYSTEM-level impact is precisely why local privilege-escalation bugs often become valuable links in a broader intrusion chain.
References
- Official MSRC or vendor evidence api.msrc.microsoft.com
- Official MSRC or vendor evidence msrc.microsoft.com
- Official MSRC or vendor evidence api.msrc.microsoft.com