Impact
The vulnerability is a race condition in the Function Discovery Service DLL that allows an authorized local attacker to gain a higher privilege level. By exploiting improper synchronization when multiple processes access a shared resource, the attacker can cause the service to run code with elevated privileges, potentially giving them administrative access to the affected system.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 22H3, and 26H1; Microsoft Windows Server 2012, Server 2012 R2, 2016, 2019, 2022, 2025, and the 23H2 Edition, including Server Core installations where applicable.
Risk and Exploitability
The CVSS score of 7 indicates a high severity risk, and the presence of the vulnerability is likely to be exploited by attackers with local access. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the issue requires concurrent execution of a shared resource, the exploitation requires some technical expertise but does not need remote access. If the attacker already has authorized access, they could trigger the race condition to elevate privilege and may subsequently gain full administrative control over the machine.
OpenCVE Enrichment