CVE-2026-50349
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock
CVSS
7.0
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Sep 8, 2026 · Last modified: Sep 8, 2026 · CWE-362 · CWE-416
Not enough EPSS history yet.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-853607.0 HIG—
———Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.4hCVE-2026-839978.1 HIG—
———Use after free in Windows Message Queuing allows an unauthorized attacker to execute code over a network.4hCVE-2026-839797.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-839687.8 HIG—
———Use after free in Windows Biometric Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-839407.0 HIG—
———Use after free in Windows Device Association Service allows an authorized attacker to elevate privileges locally.4hCVE-2026-819547.8 HIG—
———Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.4h