Impact
Concurrent execution using a shared resource within the Windows Telephony Service creates a race condition that allows an authorized local user to gain elevated privileges. The flaw stems from improper synchronization and is classified as CWE‑362.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2; Windows 11 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022, and 2025 (including Server Core). All listed operating systems contain the vulnerable Telephony Service component.
Risk and Exploitability
The CVSS score of 7.0 reflects a medium‑to‑high severity for local privilege escalation. An EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, indicating no widespread exploitation is known. Because the flaw requires an authenticated local user, the primary risk arises to internal accounts that may be compromised or have excessive privileges. The required local access is explicitly stated in the description, so the attack vector is a local privileged user exploiting the race condition.
OpenCVE Enrichment