Impact
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. The flaw is a classic synchronization error (CWE‑362) that enables a carefully timed sequence of actions to corrupt internal driver state and grant higher authority on the same machine.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, and 22H2; Windows 11 23H2, 24H2, 25H2, and 26H1; Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.0 indicates high severity, but the EPSS score of less than 1% signals a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA KEV catalog, which further suggests limited active exploitation. Since the flaw requires local access and the attacker must trigger a race condition, the attack vector is strictly local; remote exploitation is not feasible. If successfully leveraged, the privilege escalation could enable full system compromise under a high‑privilege local account.
OpenCVE Enrichment