
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24296 is a race condition vulnerability in the Windows Device Association Service that allows an authorized local attacker to elevate privileges. Classified under CWE-362 (Concurrent Execution Using Shared Resource with Improper Synchronization), it affects a broad range of Microsoft Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), Windows Server 2012 R2, 2016, 2019, 2022, and 2025. It was disclosed and patched on March 10, 2026, as part of Microsoft's March 2026 Patch Tuesday. The vulnerability carries a CVSS v3.1 base score of 7.0 (High) (Microsoft MSRC).
The vulnerability stems from improper synchronization when the Windows Device Association Service accesses shared resources during concurrent execution, classified as CWE-362 (Race Condition). An attacker with low-privilege local access can exploit the timing window between resource checks and resource use — a classic Time-of-Check to Time-of-Use (TOCTOU) pattern, mapped to CAPEC-29. Exploitation requires high attack complexity due to the need to win the race condition, but no user interaction is needed. No public proof-of-concept code has been identified at this time (Microsoft MSRC).
Successful exploitation allows an authorized local attacker to escalate privileges to SYSTEM level, potentially resulting in complete system compromise with high confidentiality, integrity, and availability impact. An attacker who wins the race condition could install malware, modify system configurations, access sensitive data, or create persistent backdoors. While the attack is local and requires an existing low-privileged account, it could serve as a critical step in a broader attack chain following initial access (Microsoft MSRC).
Microsoft released patches on March 10, 2026, addressing this vulnerability across all affected Windows versions. Administrators should apply the relevant cumulative updates to reach the following minimum build versions: Windows 10 1607 (10.0.14393.8957+), Windows 10 1809 (10.0.17763.8511+), Windows 10 21H2 (10.0.19044.7058+), Windows 10 22H2 (10.0.19045.7058+), Windows 11 23H2 (10.0.22631.6783+), Windows 11 24H2 (10.0.26100.7979+), Windows 11 25H2 (10.0.26200.7979+), Windows 11 26H1 (10.0.28000.1719+), Windows Server 2019 (10.0.17763.8511+), Windows Server 2022 (10.0.20348.4830+), and Windows Server 2025 (10.0.26100.32463+). As a complementary measure, organizations should enforce the principle of least privilege to limit the number of accounts that could be used to trigger the vulnerability, and consider restricting access to the Windows Device Association Service where operationally feasible (Microsoft MSRC).
CVE-2026-24296 was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets. Rapid7, Sophos, Zero Day Initiative, and ISC SANS all included it in their monthly patch analysis, noting it as a moderate-severity local privilege escalation without active exploitation. No significant standalone commentary or notable researcher focus was directed specifically at this CVE, consistent with its medium severity and lack of public exploit code (Zero Day Initiative, Sophos Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."