Important CVSS 7 EPSS 0.00246 🔬 Patch diffed 2026-08 archive

Executive Summary

Double free in Windows Network Connection Broker allows an authorized attacker to elevate privileges locally.

Overview

7
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Aug 11 2026
Last Updated Aug 11 2026
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.00246 — 0.16012 percentile
NVD CVSS 7 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.1

EPSS Score

0.00246
probability of exploitation in the next 30 days
0.16012 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

22 affected products
Product KB Article Severity Impact Restart Required
Windows 10 Version 1607 for 32-bit Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5120418 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5120238 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5120249 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5120240 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5120994 (Security Hotpatch Update) 5121003 (Security Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9106 10.0.26100.9168 Yes None Windows 11 Version 24H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.9168 10.0.26000.9106 Yes None Windows 11 Version 25H2 for ARM64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 25H2 for x64-based Systems 5121003 (Security Update) 5120994 (Security Hotpatch Update) Important Elevation of Privilege 5101650 Base: 7.0 Temporal: 6.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26200.9168 10.0.26100.9106 Yes None Windows 11 Version 26H1 for ARM64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows 11 version 26H1 for x64-based Systems 5121000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2012 5120386 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5120386 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5120385 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5120418 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5120238 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5120238 (Security Update) Important Elevation of Privilege Yes

Patches

7 patches
Article Type Restart
5120418 Security Update Yes
5120238 Security Update Yes
5120249 Security Update Yes
5120240 Security Update Yes
5121000 Security Update Yes
5120386 Monthly Rollup Yes
5120385 Monthly Rollup Yes

Patch Diff

ghidriff · ncbservice.dll (KB5121003)

Double free (CWE-415) via a start/stop race in the Windows Network Connection Broker service ncbservice.dll socket-broker/timer teardown, local EoP to SYSTEM (AC:H race). The NCB service (ncbservice.dll, runs as SYSTEM) sets up a socket broker on start (StartNcbService -> InitializeSocketBroker allocates global objects g_SocketBrokerTable, g_BIHelper, g_SocketBrokerConfig and arms a timer via the KAM timer manager) and tears it down on stop (InitiateStopNcbService -> CleanupSocketBroker frees those globals; KamDestroyTimer destroys the timer). PRE: the teardown was insufficiently synchronized against a concurrent start/stop (or a re-entrant/duplicate stop), so a socket-broker object or the KAM timer could be freed twice - a double free that corrupts the heap. Because the service runs as SYSTEM and start/stop is reachable by a local user, and exploitation requires winning the race (AC:H), the double free is a local EoP-to-SYSTEM primitive. Diff of ncbservice.dll 10.0.26100.8972 -> .9168 (Aug 11 2026, KB5121003) confirms the fix: gated behind CFR flags Feature_939503929 / Feature_2500799800, KamDestroyTimer is reworked (its signature simplified and its destroy path gated so the timer is destroyed at most once) and the socket-broker start/stop cleanup (InitializeSocketBroker / CleanupSocketBroker) is restructured so the broker globals are not freed twice across a start/stop race. Note: the double-free fix is confirmed as the Feature_939503929-gated rework of KamDestroyTimer and the socket-broker teardown; the exact doubly-freed object is not cleanly isolable in this diff (entangled with WIL feature-staging churn), so the mechanism is stated per the CWE-415 + AC:H classification and the observed changes.

Pre-patch version 10.0.26100.8972 Download
Post-patch version 10.0.26100.9168 Download
Function Address Change Note
KamDestroyTimer code change code (timer destroy made single-free, CFR-gated) Pre: KamDestroyTimer(param_1, param_2, param_3) could destroy/free the timer object more than once across a race. Post (Feature_939503929): reworked to KamDestroyTimer(param_1) with a gated destroy path so the timer is freed at most once.
CleanupSocketBroker code change code (socket-broker teardown restructured) Pre: freed g_SocketBrokerTable / g_BIHelper / g_SocketBrokerConfig (operator delete + NULL) without adequate protection against a concurrent/duplicate stop. Post: restructured teardown ordering to avoid freeing the broker globals twice.
InitializeSocketBroker / StartNcbService / InitiateStopNcbService code change code (start/stop synchronization updated) Service start/stop paths updated in concert so setup and teardown of the socket broker/timer do not race into a double free.
Feature_939503929 gate added (CFR gate) CFR flag (with Feature_2500799800) gating the single-free timer/teardown rework; the original path still ships when disabled.
View full diff report View RCA report

Attack Path

A race between NCB service start and stop frees the socket-broker/timer object twice

Attack path for CVE-2026-61366 A race between NCB service start and stop frees the socket-broker/timer object twice 01 — ENTRY Local user drives the Network Connection Broker service start/stop ncbservice.dll (SYSTEM) InitializeSocketBroker allocates broker globals and a KAM timer on start; CleanupSocketBroker/KamDestroyTimer free them on stop. AV:L/PR:L/AC:H (race). 02 — CONTROLLED INPUT Triggers concurrent (or duplicate) start/stop of the broker Teardown runs without adequate synchronization against a racing start/stop. 03 — MISSING CHECK A socket-broker object or the KAM timer is freed twice (CWE-415) The race lets CleanupSocketBroker / KamDestroyTimer free the same allocation more than once. 04 — PATH Double free corrupts the process heap in the SYSTEM service Controlling the reused/freed allocation influences SYSTEM-side state. 05 — PRIMITIVE Double free in the SYSTEM NCB service -> EoP to SYSTEM The Aug 2026 fix (Feature_939503929) makes the timer destroy single-free and restructures the socket-broker teardown.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

Detection Rules