CVE-2026-20869EPSS p20.5%

CVE-2026-20869CVE-2026-20869

microsoft / windows_10_1607

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Local Session Manager (LSM) allows an authorized attacker to elevate privileges locally.

Scoring

CVSS 7.0 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.30% probability of exploitation · percentile 20.5% · 2026-10-06T12:00:23Z
Last modified2026-07-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.