CVE-2026-27927
7.8Microsoft · Windows Projected File System
A race condition in the Windows Projected File System allows an authenticated attacker to elevate privileges on the local system.
Executive summary
A critical privilege escalation vulnerability in the Windows Projected File System allows authenticated attackers to gain elevated system access through a race condition.
Vulnerability
This flaw involves a concurrent execution issue with improper synchronization, specifically a race condition and a potential use after free, within the Windows Projected File System. The vulnerability requires the attacker to have local access and low privileges to execute the exploit.
Business impact
Successful exploitation of this vulnerability allows a local, authenticated attacker to escalate their privileges, potentially gaining full control over the affected system. With a CVSS score of 7.8, this vulnerability represents a high risk to organizational integrity, as it facilitates unauthorized lateral movement and the potential compromise of sensitive data stored on compromised endpoints.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft for the specified Windows versions to resolve the synchronization flaw.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected errors associated with the Windows Projected File System, which may indicate attempted exploitation.
Compensating Controls: Ensure that endpoint detection and response (EDR) solutions are configured to detect and block suspicious local privilege escalation attempts.
Exploitation status
Public Exploit Available: No (exploit_available: unknown).
Analyst recommendation
Given the potential for full privilege escalation, organizations should treat this vulnerability with high priority. IT administrators must verify their Windows build versions against the provided list and deploy the corresponding Microsoft security patches immediately to eliminate the underlying race condition.