Home
MEDIUM: 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C 10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
10.0.19044.0 (custom) before 10.0.19044.7058
affected
10.0.19045.0 (custom) before 10.0.19045.7058
affected
6.2.9200.0 (custom) before 6.2.9200.25973
affected
6.2.9200.0 (custom) before 6.2.9200.25973
affected
6.3.9600.0 (custom) before 6.3.9600.23074
affected
6.3.9600.0 (custom) before 6.3.9600.23074
affected
10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.14393.0 (custom) before 10.0.14393.8957
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
10.0.17763.0 (custom) before 10.0.17763.8511
affected
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kerberos allows an unauthorized attacker to bypass a security feature over a network.
Problem types
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2026-24297 (Windows Kerberos Security Feature Bypass Vulnerability)