# CVE-2026-61366 — Windows Network Connection Broker `ncbservice.dll` Start/Stop Race in Socket-Broker/Timer Teardown → Double Free

---

## Summary

| | |
|---|---|
| **Product** | Windows — `ncbservice.dll` (Network Connection Broker service, runs as SYSTEM) |
| **CVE ID** | CVE-2026-61366 |
| **Impact** | Elevation of Privilege (to SYSTEM) |
| **MSRC severity** | Important |
| **CVSS** | 7.0 / 6.1 — `CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C` |
| **CWE** | CWE-415: Double Free (race-triggered) |
| **Delivery** | Local — a race between NCB service start and stop |
| **KB / Fixed build** | KB5121003 — `ncbservice.dll` 10.0.26100.9168 (Win11 24H2 x64) |
| **Patch Date** | August 11, 2026 (2026-Aug) |
| **Pre-patch binary** | `ncbservice.dll` 10.0.26100.8972 — SHA256 `189536592b6508a1a1ba708894b198c67c5fdd978a2e14c79d8001a7414b03f0` |
| **Post-patch binary** | `ncbservice.dll` 10.0.26100.9168 — SHA256 `4e56f1b092b0d1393435900793042197269770b4b041eff3b9b00e56e5fb4d19` |
| **Feature flag** | `Feature_939503929` (also `Feature_2500799800`) — **CFR-gated** |
| **Exploitability** | Exploitation Less Likely; not publicly disclosed; not exploited (per MSRC) |

---

## Product Description

`ncbservice.dll` implements the Windows **Network Connection Broker** service, which
runs as SYSTEM. On start (`StartNcbService` → `InitializeSocketBroker`) it allocates
global broker objects — `g_SocketBrokerTable`, `g_BIHelper`, `g_SocketBrokerConfig` —
and arms a timer through the KAM timer manager. On stop
(`InitiateStopNcbService` → `CleanupSocketBroker`) it frees those globals, and
`KamDestroyTimer` destroys the timer.

---

## Vulnerability Summary

The teardown was **insufficiently synchronized** against a concurrent start/stop (or
a re-entrant / duplicate stop), so a socket-broker object or the KAM timer could be
freed **twice** — a double free that corrupts the process heap (CWE-415). Because the
service runs as SYSTEM and its start/stop is reachable by a local user, and
exploitation requires winning the race (`AC:H`), the double free is a local
elevation-of-privilege primitive to SYSTEM (per the MSRC FAQ).

> Confirmation: the fix is confirmed as the `Feature_939503929`-gated rework of
> `KamDestroyTimer` and the socket-broker teardown; the exact doubly-freed object is
> not cleanly isolable in this diff (entangled with WIL feature-staging churn), so
> the mechanism follows the CWE-415 + `AC:H` classification and the observed changes.

---

## Prerequisites and Constraints

- Local, low-privileged (`PR:L`, `AV:L`); `AC:H` — must win a race between NCB service
  start and stop (or induce a duplicate stop).
- Result: a socket-broker object / the KAM timer is freed twice.

---

## Vulnerability Details

### Root Cause

The socket-broker/timer teardown freed shared global objects without adequate
protection against a concurrent or duplicate stop, so the same allocation could be
released more than once.

### The patch (confirmed — diff, .8972 → .9168)

Gated behind `Feature_939503929` (and `Feature_2500799800`), the timer-destroy and
socket-broker teardown are reworked to be single-free:

```c
// KamDestroyTimer — signature simplified and destroy path gated (from our diff)
// pre : KamDestroyTimer(longlong param_1, undefined8 param_2, undefined *param_3)
// post: KamDestroyTimer(longlong param_1)   // gated under Feature_939503929; destroy at most once

// CleanupSocketBroker (pre) freed the broker globals directly:
//   if (g_SocketBrokerTable) { operator delete[](...); g_SocketBrokerTable = NULL; }
//   if (g_BIHelper)          { operator delete[](...); g_BIHelper = NULL; }
//   if (g_SocketBrokerConfig){ operator delete[](g_SocketBrokerConfig); ... }
// post: teardown restructured so these are not freed twice across a start/stop race.
```

With the timer destroyed at most once and the socket-broker teardown restructured,
a racing/duplicate stop can no longer free the same object twice, closing the double
free.

### Patch Completeness Assessment

**CFR-gated behind `Feature_939503929`.** The single-free teardown runs only when the
flag is enabled; the original path still ships when disabled. Verify
`Feature_939503929` is enabled to confirm the fix is live.

---

## Detection Guidance

**Behavioural.** Rapid / concurrent start-stop cycling of the Network Connection
Broker service; double-free / heap-corruption crashes in
`ncbservice!CleanupSocketBroker` / `KamDestroyTimer` on unpatched/flag-disabled
builds.

**Config.** The fix is CFR-gated — confirm `Feature_939503929` is enabled.

---

## References

- MSRC advisory — CVE-2026-61366 (Windows Network Connection Broker Elevation of Privilege), released 2026-08-11, KB5121003.
- Full binary diff: `/data/patch_diffs/ncbservice_dll-cve-2026-61366-ghidriff.md`
