Impact
The vulnerability is a race condition in the Windows Ancillary Function Driver for WinSock caused by concurrent execution using a shared resource with improper synchronization. An authorized local attacker can exploit this flaw (CWE‑362) to elevate privileges locally on the host.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.0 indicates high severity, but the EPSS score of less than 1% signals a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, which further suggests limited active exploitation. Since the flaw requires local access and the attacker must trigger a race condition, the attack vector is strictly local; remote exploitation is not feasible. If successfully leveraged, the privilege escalation could enable full system compromise under a high‑privilege local account.
OpenCVE Enrichment