Impact
The vulnerability is a race condition in Windows WalletService caused by improper synchronization of shared resources. An unauthorized local attacker can trigger concurrent execution paths and gain elevated privileges, effectively turning a standard user account into an administrator.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2, and Microsoft Windows 11 versions 22H3, 23H2, 24H2, and 25H2 are affected.
Risk and Exploitability
The CVSS score is 7.4, indicating high severity, but the EPSS score is less than 1%, showing a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Because it requires local code execution or user interaction, the attack vector is inferred to be local privilege escalation rather than remote exploitation.
OpenCVE Enrichment