CVE-2026-58598
published 2026-07-16CVE-2026-58598: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate…
PriorityP336high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.19%
9.1th percentile
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.7548 | 10.0.19044.7548 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.7548 | 10.0.19045.7548 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.8875 | 10.0.26100.8875 |
| microsoft | windows_11_version_25h2 | >= 10.0.26200.0 < 10.0.26100.8875 | 10.0.26100.8875 |
| microsoft | windows_11_version_26h1 | >= 10.0.28000.0 < 10.0.28000.2525 | 10.0.28000.2525 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
ghsa_unreviewed·2026-07-17
CVE-2026-58598 [HIGH] CWE-362 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Backup Engine allows an authorized attacker to elevate privileges locally.
VulDB
Microsoft Windows up to 11 26H1 Backup Engine race condition
vuldb·2026-07-17·CVSS 7.0
CVE-2026-58598 [HIGH] Microsoft Windows up to 11 26H1 Backup Engine race condition
A vulnerability categorized as problematic has been discovered in Microsoft Windows 10 21H2/10 22H2/11 24H2/11 25H2/11 26H1. This impacts an unknown function of the component Backup Engine. The manipulation results in race condition.
This vulnerability is cataloged as CVE-2026-58598. The attack must be initiated from a local position. There is no exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-16
Published