
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-24297 is a race condition vulnerability in Windows Kerberos that allows an unauthorized network attacker to bypass a security feature. It was disclosed by Microsoft on March 10, 2026, as part of the March 2026 Patch Tuesday security update cycle. Affected products include Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows Server 2012, 2012 R2, 2016, and 2019. The vulnerability carries a CVSS v3.1 base score of 4.8 (Medium) per Microsoft's advisory (Microsoft MSRC).
The root cause is classified as CWE-362 (Concurrent Execution Using Shared Resource with Improper Synchronization — Race Condition) within the Windows Kerberos authentication subsystem. An attacker can exploit a timing window during concurrent execution to manipulate a shared resource, bypassing Kerberos security controls without requiring authentication or user interaction. The attack is network-based and requires high attack complexity, meaning the attacker must engineer specific timing conditions to win the race. No public proof-of-concept code has been identified at this time (Microsoft MSRC).
Successful exploitation allows a network-based, unauthenticated attacker to bypass Kerberos security features, resulting in limited confidentiality and integrity impacts (both rated Low). The vulnerability does not affect availability. In environments where Kerberos is central to authentication — particularly Active Directory domains — a successful bypass could undermine trust in authentication mechanisms, potentially enabling unauthorized access to resources or facilitating further attacks such as ticket manipulation or lateral movement (Microsoft MSRC).
Microsoft released patches on March 10, 2026, addressing this vulnerability across all affected platforms. Administrators should apply the following updates: Windows 10 21H2 → build 10.0.19044.7058, Windows 10 22H2 → build 10.0.19045.7058, Windows 10 1809 / Windows Server 2019 → build 10.0.17763.8511, Windows 10 1607 / Windows Server 2016 → build 10.0.14393.8957, Windows Server 2012 R2 → build 6.3.9600.23074, and Windows Server 2012 → build 6.2.9200.25973. Domain controllers and Windows Server systems should be prioritized for patching given their critical role in Kerberos authentication. No configuration-based workarounds have been published (Microsoft MSRC).
The vulnerability was covered as part of broader March 2026 Patch Tuesday roundups by multiple security outlets including BleepingComputer, Rapid7, Zero Day Initiative, Sophos, and CyberSecurityNews, though CVE-2026-24297 did not receive individual spotlight coverage due to its medium severity and lack of active exploitation (Rapid7 Blog, ZDI Blog, Sophos Blog). Community sentiment reflected routine patch prioritization guidance, with analysts noting the high attack complexity as a mitigating factor.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."