Impact
The Windows Speech Brokered API contains a race condition caused by improper synchronization of a shared resource. An authorized local attacker can manipulate the timing of concurrent operations to elevate process privileges, potentially allowing execution of arbitrary code with higher permissions on the system.
Affected Systems
Affected systems include Microsoft Windows 10 from version 1607 to 22H2, Windows 11 from 23H2 onward, and Windows Server 2016, 2019, 2022, 2025, and 23H2 editions. These systems run on x86, x64, and ARM64 architectures as indicated in vendor advisories.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, requiring an authorized user to trigger the race condition using the brokered API. Exploitation relies on improper lock handling that allows privilege escalation within the local environment.
OpenCVE Enrichment