Impact
The flaw resides in the Windows App Installer service, where two processes can concurrently access a shared resource without proper synchronization. This race condition, an improper synchronization failure (CWE-362) coupled with a potential use‑after‑free (CWE-416), allows a locally authenticated user to manipulate execution ordering and gain elevated privileges. The attacker can execute code with increased authority, undermining the confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected versions include Microsoft Windows 11 23 H2 (x64 and arm64), 24 H2, 25 H2, 26 H1 (arm64), and Microsoft Windows Server 2025 (including Server Core). The x64 build is only impacted in Windows 11 23 H2, while arm64 builds are impacted across the listed versions.
Risk and Exploitability
The CVSS score of 7 classifies this vulnerability as high severity, yet the EPSS score is below 1 %, indicating a very low current exploitation probability. It is not listed in CISA’s KEV catalog, so no large‑scale campaigns are documented. Exploitation requires a local user with the ability to run code and trigger the race, making it most relevant to insiders or malware already resident on the target machine.
OpenCVE Enrichment