Impact
Concurrent execution using a shared resource in the UI Automation Manager component exposes a race condition that allows an attacker with local authorization to elevate privileges. The flaw arises from improper synchronization when multiple threads access or modify the same resource. If successfully exploited, the attacker can gain higher privileges than intended, potentially enabling them to execute arbitrary code with elevated rights within the local system. The vulnerability is classified as a race condition (CWE-362).
Affected Systems
Microsoft Windows 11 versions 23H2, 24H2, 25H2, and 26H1; Microsoft Windows Server 2022; Microsoft Windows Server 2025 (including Server Core installation). These are the specific operating system releases explicitly mentioned as affected.
Risk and Exploitability
The CVSS base score of 7 indicates a high severity level. The exploit is local, requiring that the attacker already has a foothold on the machine. The EPSS score is currently unavailable, so the exact likelihood of exploitation is uncertain. The vulnerability is not listed in CISA’s KEV catalog, suggesting that no widespread, confirmed exploits are known at this time. Nonetheless, it remains a significant risk for users running the affected Windows releases and should be addressed promptly.
OpenCVE Enrichment