Impact
A race condition in Microsoft Function Discovery Service (fdwsd.dll) allows an attacker with local authorized access to exploit improper synchronization and elevate privileges. The flaw involves concurrent execution using a shared resource, enabling privilege escalation within the local system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 22H3, 26H1; Windows Server installations from 2012 through 2025, including Core and non‑Core editions. All affected client and server configurations are listed from the CNA vendor information.
Risk and Exploitability
The CVSS score of 7 indicates high impact. EPSS is not available and it is not listed in the CISA KEV catalog, but the vulnerability can be leveraged by any local user who already has authenticated access and can coordinate concurrent requests to trigger the race condition. Successful exploitation results in elevation of privileges to local system level, potentially giving full control of the affected machine.
OpenCVE Enrichment