
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20919 is a race condition vulnerability in the Windows SMB Server component that allows an authenticated attacker with low privileges to elevate their privileges over a network. Classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization), it was disclosed and patched by Microsoft on January 13, 2026, as part of the January 2026 Patch Tuesday release. Affected platforms span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2012/2012 R2, 2016, 2019, 2022, 2022 23H2, and 2025. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The root cause is improper synchronization of shared resources during concurrent execution within the Windows SMB Server (CWE-362), a classic time-of-check to time-of-use (TOCTOU) style race condition (CAPEC-29). An attacker with low-level network access and valid credentials can exploit the timing window created by the race condition to manipulate shared state and gain elevated privileges. The attack vector is network-based, requires low privileges, no user interaction, and has high attack complexity — meaning the attacker must carefully time or repeatedly attempt the exploit to win the race. No public proof-of-concept code has been identified at the time of disclosure (Microsoft MSRC, Feedly).
Successful exploitation allows an authenticated attacker to escalate privileges to SYSTEM level on the targeted Windows host via the SMB Server over the network, resulting in high confidentiality, integrity, and availability impact. This level of access enables arbitrary code execution, persistence mechanisms, and lateral movement across Windows infrastructure — particularly dangerous in environments where SMB is broadly accessible between systems such as domain controllers and file servers. The broad scope of affected Windows versions (from Windows Server 2012 to Windows Server 2025) significantly widens the potential attack surface (Feedly).
Microsoft released patches for all affected Windows versions on January 13, 2026, as part of the January 2026 Patch Tuesday update. Administrators should prioritize applying the following minimum build versions: Windows Server 2025 (10.0.26100.32230), Windows Server 2022 23H2 (10.0.25398.2092), Windows Server 2022 (10.0.20348.4648), Windows Server 2019 (10.0.17763.8276), Windows Server 2016 (10.0.14393.8783), Windows 11 25H2 (10.0.26200.7623), Windows 11 24H2 (10.0.26100.7623), Windows 11 23H2 (10.0.22631.6491), Windows 10 22H2 (10.0.19045.6809), Windows 10 21H2 (10.0.19044.6809), Windows 10 1809 (10.0.17763.8276), and Windows 10 1607 (10.0.14393.8783). As a compensating control, organizations should implement network segmentation to restrict SMB traffic (TCP 445) to only trusted and necessary systems, and monitor for anomalous privilege escalation activity on SMB-exposed hosts (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader January 2026 Patch Tuesday reporting, with security outlets such as BleepingComputer, Sophos, and CyberSecurityNews noting it among the 114 CVEs addressed that month. Sophos highlighted the SMB-related privilege escalation risk in their Patch Tuesday analysis. A community blog post (cryptobivash.code.blog) published a tool called "SMB Zero-Day Auditor v1.1" referencing this CVE, though its reliability is unverified. No major vendor statements beyond the Microsoft advisory have been issued specifically for this vulnerability (BleepingComputer, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."