
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-20921 is a race condition vulnerability in the Windows SMB Server component that allows an authorized, low-privileged attacker to elevate privileges over a network. Classified under CWE-362 (Concurrent Execution using Shared Resource with Improper Synchronization), it was disclosed and patched on January 13, 2026, as part of Microsoft's January 2026 Patch Tuesday. Affected platforms span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2008 through 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Microsoft MSRC, Feedly).
The vulnerability stems from improper synchronization of shared resources within the Windows SMB Server during concurrent execution (CWE-362), which can be exploited as a race condition — specifically a Time-of-Check to Time-of-Use (TOCTOU) pattern (CAPEC-29). An attacker with low-level network access and valid credentials can trigger the race condition to gain elevated privileges without requiring user interaction. The attack vector is network-based with high attack complexity, meaning the attacker must win a timing race to successfully exploit the flaw. Detection and remediation scripts have been published by Vicarius, indicating some level of technical analysis is publicly available (Microsoft MSRC, Vicarius Detection).
Successful exploitation allows an authorized but low-privileged attacker to escalate to system-level privileges on the affected Windows host, resulting in full compromise of confidentiality, integrity, and availability. An attacker achieving elevated privileges could access sensitive data, modify system configurations, install malware, or pivot laterally within the network. The broad scope of affected systems — from legacy Windows Server 2008 SP2 through modern Windows Server 2025 and Windows 11 25H2 — significantly widens the potential attack surface in enterprise environments (Feedly).
nmap -p 445 <target>) or Shodan, targeting versions prior to the January 2026 patches.svchost.exe spawning cmd.exe or powershell.exe).C:\Windows\System32\) by accounts that should not have write access; unexpected scheduled tasks or services created post-exploitation.Microsoft released patches on January 13, 2026, addressing this vulnerability across all affected platforms. Patched build versions include: Windows 10 1607 (10.0.14393.8783), Windows 10 1809/Server 2019 (10.0.17763.8276), Windows 10 21H2 (10.0.19044.6809), Windows 10 22H2 (10.0.19045.6809), Windows 11 23H2 (10.0.22631.6491), Windows 11 24H2 (10.0.26100.7623), Windows 11 25H2 (10.0.26200.7623), Windows Server 2012 R2 (6.3.9600.22968), Windows Server 2016 (10.0.14393.8783), Windows Server 2022 (10.0.20348.4648), Windows Server 2022 23H2 (10.0.25398.2092), and Windows Server 2025 (10.0.26100.32230). As interim mitigations: restrict SMB access at the network perimeter using firewalls to block TCP port 445 from untrusted networks, disable SMBv1 if not required, implement network segmentation to limit lateral movement, and monitor SMB authentication activity for anomalies (Microsoft MSRC, Feedly).
CVE-2026-20921 was covered as part of broader reporting on Microsoft's January 2026 Patch Tuesday, which addressed 114 vulnerabilities including 3 zero-days. Security outlets including BleepingComputer, CyberSecurityNews, GBHackers, and SANS ISC Diary covered the patch release, with general community focus on the zero-day vulnerabilities rather than this specific CVE. Sophos also published analysis of the January 2026 Patch Tuesday batch. No specific researcher commentary or notable social media discussion targeting this CVE individually has been identified (BleepingComputer, SANS ISC, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."