CVE-2022-26928: Windows 10 Race Condition (CVSS 7)

CVE-2022-26928 is a high-severity vulnerability rated 7/10 on the CVSS scale. Windows Photo Import API Elevation of Privilege Vulnerability. EPSS estimates a 0.70% chance of exploitation in the next 30 days.

Description

Windows Photo Import API Elevation of Privilege Vulnerability

Metrics

CVSS 3.17/10

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability 0.70%

48.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

Vendor Product Versions
Microsoft Windows 10 All versions
Microsoft Windows 10 20h2
Microsoft Windows 10 21h1
Microsoft Windows 10 21h2
Microsoft Windows 10 1607
Microsoft Windows 10 1809
Microsoft Windows 11 All versions
Microsoft Windows Server 2016 All versions
Microsoft Windows Server 2019 All versions
Microsoft Windows Server 2022 All versions

References

Timeline

Published: Sep 13, 2022

Last Modified: Jun 17, 2026

Status: Modified

Frequently Asked Questions

What is CVE-2022-26928?

Windows Photo Import API Elevation of Privilege Vulnerability

How severe is CVE-2022-26928?

CVE-2022-26928 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 0.70% probability of exploitation in the next 30 days.

How do I fix CVE-2022-26928?

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.