CVE-2026-20869: Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.
Other sources
Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.28117Patch KB5073699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23717Patch KB5073700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20869?
The severity of CVE-2026-20869 is classified as a high elevation of privilege vulnerability.
How do I fix CVE-2026-20869?
To fix CVE-2026-20869, install the latest security updates provided by Microsoft for the affected Windows versions.
Which Microsoft products are affected by CVE-2026-20869?
CVE-2026-20869 affects multiple versions of Windows, including Windows 10, Windows 11, Windows Server 2022, and Windows Server 2019.
Can CVE-2026-20869 be exploited remotely?
CVE-2026-20869 is a local privilege escalation vulnerability and cannot be exploited remotely.
What type of vulnerability is CVE-2026-20869?
CVE-2026-20869 is a race condition vulnerability in the Windows Local Session Manager.