MicrosoftCVE-2026-68824
Microsoft Windows Connected User Experiences: race condition
High7.0CVE-2026-68824 · Published Sep 8, 2026 · updated Sep 17, 2026
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected User Experiences and Telemetry allows an authorized attacker to elevate privileges locally.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Windows 10 Version 21H2 Product | >= 10.0.19044.0, < 10.0.19044.7725 | 10.0.19044.7725 |
| Windows 10 Version 22H2 Product | >= 10.0.19045.0, < 10.0.19045.7725 | 10.0.19045.7725 |
| Windows 11 Version 23H2 Product | >= 10.0.22631.0, < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 Version 24H2 Product | >= 10.0.26100.0, < 10.0.26100.9445 | 10.0.26100.9445 |
| Windows 11 Version 25H2 Product | >= 10.0.26200.0, < 10.0.26200.9445 | 10.0.26200.9445 |
| Windows 11 version 23H2 Product | >= 10.0.22631.0, < 10.0.22631.7582 | 10.0.22631.7582 |
| Windows 11 version 26H1 Product | >= 10.0.28000.0, < 10.0.28000.2954 | 10.0.28000.2954 |
| Windows Server 2022 Product | >= 10.0.20348.0, < 10.0.20348.5622 | 10.0.20348.5622 |
| Windows Server 2025 Product | >= 10.0.26100.0, < 10.0.26100.33438 | 10.0.26100.33438 |
| Windows Server 2025 (Server Core installation) Product | >= 10.0.26100.0, < 10.0.26100.33438 | 10.0.26100.33438 |
Details and references
More Microsoft advisories
All Microsoft| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 8 | Microsoft Skype for Business: spoofing | High8.3 | 6.0.9319.885+2 more |
| Sep 8 | Microsoft Skype for Business: cross-site scripting | Medium6.5 | 6.0.9319.885+2 more |
| Sep 8 | Microsoft Skype for Business: spoofing | High7.1 | 6.0.9319.885+2 more |
| Sep 8 | Microsoft Skype for Business: information disclosure | Medium6.5 | 6.0.9319.885+2 more |
| Sep 8 | Microsoft Skype for Business: integer overflow | High7.5 | 6.0.9319.885+2 more |
| Sep 8 | Microsoft Skype for Business: out-of-bounds read | Medium6.5 | 6.0.9319.885+2 more |