CVE-2026-61366 — Windows Network Connection Broker Elevation of Privilege Vulnerability
Executive Summary
Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 Version 1607 for 32-bit Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5120249 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5120240 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows 11 version 26H1 for x64-based Systems | 5121000 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 | 5120386 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 (Server Core installation) | 5120386 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5120385 (Monthly Rollup) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2016 (Server Core installation) | 5120418 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
| Windows Server 2019 (Server Core installation) | 5120238 (Security Update) |
Important | Elevation of Privilege | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5120418 |
Security Update | Yes |
5120238 |
Security Update | Yes |
5120249 |
Security Update | Yes |
5120240 |
Security Update | Yes |
5121000 |
Security Update | Yes |
5120386 |
Monthly Rollup | Yes |
5120385 |
Monthly Rollup | Yes |
Patch Diff
Double free (CWE-415) via a start/stop race in the Windows Network Connection Broker service ncbservice.dll socket-broker/timer teardown, local EoP to SYSTEM (AC:H race). The NCB service (ncbservice.dll, runs as SYSTEM) sets up a socket broker on start (StartNcbService -> InitializeSocketBroker allocates global objects g_SocketBrokerTable, g_BIHelper, g_SocketBrokerConfig and arms a timer via the KAM timer manager) and tears it down on stop (InitiateStopNcbService -> CleanupSocketBroker frees those globals; KamDestroyTimer destroys the timer). PRE: the teardown was insufficiently synchronized against a concurrent start/stop (or a re-entrant/duplicate stop), so a socket-broker object or the KAM timer could be freed twice - a double free that corrupts the heap. Because the service runs as SYSTEM and start/stop is reachable by a local user, and exploitation requires winning the race (AC:H), the double free is a local EoP-to-SYSTEM primitive. Diff of ncbservice.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flags Feature_939503929 / Feature_2500799800, KamDestroyTimer is reworked (its signature simplified and its destroy path gated so the timer is destroyed at most once) and the socket-broker start/stop cleanup (InitializeSocketBroker / CleanupSocketBroker) is restructured so the broker globals are not freed twice across a start/stop race. Note: the double-free fix is confirmed as the Feature_939503929-gated rework of KamDestroyTimer and the socket-broker teardown; the exact doubly-freed object is not cleanly isolable in this diff (entangled with WIL feature-staging churn), so the mechanism is stated per the CWE-415 + AC:H classification and the observed changes.
| Function | Address | Change | Note |
|---|---|---|---|
KamDestroyTimer |
code change |
code (timer destroy made single-free, CFR-gated) | Pre: KamDestroyTimer(param_1, param_2, param_3) could destroy/free the timer object more than once across a race. Post (Feature_939503929): reworked to KamDestroyTimer(param_1) with a gated destroy path so the timer is freed at most once. |
CleanupSocketBroker |
code change |
code (socket-broker teardown restructured) | Pre: freed g_SocketBrokerTable / g_BIHelper / g_SocketBrokerConfig (operator delete + NULL) without adequate protection against a concurrent/duplicate stop. Post: restructured teardown ordering to avoid freeing the broker globals twice. |
InitializeSocketBroker / StartNcbService / InitiateStopNcbService |
code change |
code (start/stop synchronization updated) | Service start/stop paths updated in concert so setup and teardown of the socket broker/timer do not race into a double free. |
Feature_939503929 |
gate |
added (CFR gate) | CFR flag (with Feature_2500799800) gating the single-free timer/teardown rework; the original path still ships when disabled. |
Attack Path
A race between NCB service start and stop frees the socket-broker/timer object twice
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
Detection Rules
Acknowledgments
Anonymous
Jongseong Kim (nevul37), SEC-agent team
Hwiwon Lee (hwiwonl), SEC-agent team
Younggi Park (grill66), SEC-agent team
Dongjun Kim (nevul37), SEC-agent team