Impact
Concurrent execution using a shared resource with improper synchronization (a race condition) exists in the Windows SMB Server. The flaw allows an authorized network user to elevate their privilege level on the host. The effect is an escalation of privileges that can enable the attacker to run code or gain administrative access on the affected machine.
Affected Systems
Microsoft Windows 10 releases starting with version 1607—including 1809, 21H2, 22H2—and Windows 11 editions 23H2, 24H2, 25H2 and 22H3, as well as Windows Server 2008 R2 SP1, 2008 SP2, 2012, 2012 R2, 2016, 2019, 2022, 2025 and their corresponding Server Core installations are affected.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score of 1.15 % suggests a low likelihood of exploitation at present and the vulnerability is not listed in the CISA KEV catalog. The most likely attack vector, inferred from the description, is over the SMB service on the network, requiring the attacker to already have authenticated or authorized access to the SMB share.
OpenCVE Enrichment