CVE-2026-58848
In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escal
CVSS
7.0
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 8 sept 2026 · Última mod.: 8 sept 2026 · CWE-362
Sin historial EPSS suficiente todavía.
In multiple functions of alloc.c, there is a possible unauthorized read/write access due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-778947.0 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Installer allows an authorized attacker to elevate privileges locally.6hCVE-2026-730057.0 ALT—
———Use after free in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.8hCVE-2026-705826.4 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Instrumentation allows an authorized attacker to elevate privileges locally.8hCVE-2026-700915.9 MED—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows DNS allows an unauthorized attacker to deny service over a network.7hCVE-2026-698278.1 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in DNS Server allows an unauthorized attacker to execute code over a network.8hCVE-2026-697997.8 ALT—
———Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hello allows an authorized attacker to elevate privileges locally.8h