CVE-2026-54107: Windows Win32k Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K allows an authorized attacker to elevate privileges locally.
Other sources
Windows Win32k Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.7548Patch KB5099539 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.5386Patch KB5099540 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.9020Patch KB5099538 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.23291Patch KB5099444 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.26226Patch KB5099445 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.9339Patch KB5099535 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.28000.2525Patch KB5101649 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.8875Patch KB5101650 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.33158Patch KB5099536
Event History
Frequently Asked Questions
What is the severity of CVE-2026-54107?
The severity of CVE-2026-54107 is classified as high with a CVSS score of 8.8.
How does CVE-2026-54107 affect systems?
CVE-2026-54107 affects Windows operating systems by allowing authorized attackers to elevate their privileges locally due to a race condition.
What versions of Windows are impacted by CVE-2026-54107?
CVE-2026-54107 affects Microsoft Windows 10, Windows 11, and various versions of Windows Server ranging from 2012 to 2025.
How do I fix CVE-2026-54107?
To fix CVE-2026-54107, ensure that your Windows operating system is updated with the latest security patches from Microsoft.
What type of vulnerability is CVE-2026-54107 classified as?
CVE-2026-54107 is classified as a race condition vulnerability that leads to potential elevation of privilege.