
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21237 is a local privilege escalation vulnerability in Windows Subsystem for Linux (WSL) caused by a race condition and use-after-free flaw stemming from improper synchronization of shared resources. Disclosed on February 10, 2026, as part of Microsoft's Patch Tuesday, it affects Windows 10 (21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), Windows Server 2022, Windows Server 2022 23H2, and Windows Server 2025. It carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC).
The vulnerability is classified under CWE-362 (Concurrent Execution Using Shared Resource with Improper Synchronization / Race Condition) and CWE-416 (Use After Free). An attacker exploits a timing window in WSL's handling of shared resources — by winning the race condition, they can trigger a use-after-free condition that allows execution of code at elevated privilege levels. Exploitation requires local access with low-privilege credentials and involves high attack complexity, as the attacker must reliably win the race window. Attack patterns align with CAPEC-26 (Leveraging Race Conditions) and CAPEC-29 (TOCTOU Race Conditions) (Microsoft MSRC).
Successful exploitation allows an authenticated local attacker with low privileges to escalate to higher privilege levels on the affected system, with high impact to confidentiality, integrity, and availability. An attacker who achieves privilege escalation could gain complete control of the affected Windows host, potentially enabling persistence, credential harvesting, or lateral movement within a network. The scope is limited to the affected system (unchanged scope), but the combination of full CIA impact makes this a significant threat in multi-user or shared environments (Microsoft MSRC).
Microsoft released patches on February 10, 2026, addressing this vulnerability across all affected platforms. Administrators should apply the following minimum build versions: Windows 10 21H2 → 10.0.19044.6937, Windows 10 22H2 → 10.0.19045.6937, Windows 11 23H2 → 10.0.22631.6649, Windows 11 24H2 → 10.0.26100.7781, Windows 11 25H2 → 10.0.26200.7781, Windows Server 2022 → 10.0.20348.4711, Windows Server 2022 23H2 → 10.0.25398.2149, Windows Server 2025 → 10.0.26100.32313. As a defense-in-depth measure, enforce the principle of least privilege to limit the pool of users who could attempt exploitation, and monitor for anomalous local privilege escalation activity (Microsoft MSRC).
The February 2026 Patch Tuesday was broadly covered by security outlets, with Bleeping Computer noting the release fixed 58 flaws including 6 zero-days, though CVE-2026-21237 was not among the actively exploited issues (BleepingComputer). Qualys and Rapid7 included the vulnerability in their Patch Tuesday review roundups, categorizing it as a moderate-priority WSL privilege escalation (Qualys Blog, Rapid7 Blog). Sophos also covered the February update in its Patch Tuesday analysis (Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."