Impact
The vulnerability is a race condition that results from insufficient synchronization of shared resources within the Windows App Store. An attacker can trigger a concurrent execution path that leads to an unauthorized privilege escalation (CWE‑362). The flaw allows a non‑privileged user to gain elevated permissions on the local machine.
Affected Systems
The flaw affects a broad range of Microsoft operating systems. Consumers of Windows 10 build 1607, 1809, 21H2, and 22H2, Windows 11 builds 24H2, 25H2, and 26H1, as well as Windows Server editions 2016, 2019, 2022, and 2025 (including core installations) are potentially vulnerable. Systems running these operating systems without the vendor’s update remain exposed.
Risk and Exploitability
The CVSS score of 8.1 classifies the flaw as high severity, but the EPSS score of <1% indicates a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is inferred to be a network‑based attack where a malicious actor on the same network can trigger the race condition against a legitimate user. The combined risk is moderate to high for organizations that allow Windows App Store usage by non‑privileged accounts and that maintain open network access to the affected machines.
OpenCVE Enrichment