PT-2026-24272 · Microsoft · Cdd+3

Marcin Wiazowski

·

Published

2026-03-10

·

Updated

2026-03-17

·

CVE-2026-23668

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description A race condition exists in the Microsoft Graphics Component due to improper synchronization when handling concurrent execution with shared resources. This allows a local attacker to elevate privileges. The issue is also described as an improper locking vulnerability in Microsoft Windows cdd and win32kfull components, leading to local privilege escalation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Race Condition

Weakness Enumeration

Related Identifiers

BDU:2026-02986
CVE-2026-23668
ZDI-26-178
ZDI-26-179
ZDI-26-180

Affected Products

Graphics
Windows
Cdd
Win32Kfull