• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-54107: local privilege escalation in Microsoft Windows 10 Version 1607

An authorized local user can elevate privileges on Windows systems due to a race condition in the Win32K component (CVE-2026-54107). The flaw affects Windows 10 Version 1607 and multiple other Windows 10, Windows 11 and Windows Server branches; affected builds are listed by vendor and are fixed at specific build numbers. An attacker needs local access with an account on the target host to trigger the improper synchronization and gain higher privileges.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
7HIGH
EPSS
0.00214
CWE
CWE-362
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this Win32K race condition, so prioritize installing the vendor updates that move affected builds to the fixed builds listed by Microsoft.

What is CVE-2026-54107?

An authorized local user can elevate privileges on Windows systems due to a race condition in the Win32K component (CVE-2026-54107). The flaw affects Windows 10 Version 1607 and multiple other Windows 10, Windows 11 and Windows Server branches; affected builds are listed by vendor and are fixed at specific build numbers. An attacker needs local access with an account on the target host to trigger the improper synchronization and gain higher privileges.

Vector CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of Microsoft Windows 10 Version 1607 are affected?

BRANCHAFFECTEDFIXED
Windows 10 Version 1607 10.x10.0.14393.0 – before 10.0.14393.933910.0.14393.9339
Windows 10 Version 1809 10.x10.0.17763.0 – before 10.0.17763.902010.0.17763.9020
Windows 10 Version 21H2 10.x10.0.19044.0 – before 10.0.19044.754810.0.19044.7548
Windows 10 Version 22H2 10.x10.0.19045.0 – before 10.0.19045.754810.0.19045.7548
Windows 11 Version 24H2 10.x10.0.26100.0 – before 10.0.26100.887510.0.26100.8875
Windows 11 Version 25H2 10.x10.0.26200.0 – before 10.0.26200.887510.0.26200.8875
Windows 11 version 26H1 10.x10.0.28000.0 – before 10.0.28000.252510.0.28000.2525
Windows Server 2012 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 (Server Core installation) 6.x6.2.9200.0 – before 6.2.9200.262266.2.9200.26226
Windows Server 2012 R2 6.x6.3.9600.0 – before 6.3.9600.232916.3.9600.23291

Is CVE-2026-54107 being exploited?

Public exploit code is available.

How to fix CVE-2026-54107

  1. Install the Microsoft updates that update affected builds to the fixed builds (for example 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, and 6.3.9600.23291).
  2. If you cannot patch immediately, restrict untrusted local accounts and remove unnecessary local admin rights.
  3. Monitor endpoints for signs of local privilege escalation and review process creation and privilege change events.

Frequently asked questions

Is CVE-2026-54107 being actively exploited?

Public exploit code is available for CVE-2026-54107.

Which Windows versions are affected by CVE-2026-54107?

CVE-2026-54107 affects Windows 10 Version 1607 and multiple other Windows 10, Windows 11 and Windows Server branches; vendor advisories list the exact affected build ranges and fixed build numbers.

Is there a patch for CVE-2026-54107?

Yes; Microsoft released fixes that update affected builds to specific fixed builds such as 10.0.14393.9339, 10.0.17763.9020, 10.0.19044.7548, 10.0.19045.7548, 10.0.26100.8875, 10.0.26200.8875, 10.0.28000.2525, 6.2.9200.26226, and 6.3.9600.23291.

Does CVE-2026-54107 require authentication?

Yes; the vulnerability requires an authorized local account on the affected Windows host to exploit the Win32K race condition.

References