Impact
The vulnerability is a race condition in the Windows Clipboard Server where concurrent access to a shared resource is not properly synchronized, allowing an authorized local attacker to elevate privileges. This flaw is categorized as CWE-362 and CWE-416, indicating an improper synchronization of concurrent operations and the use after free of a resource.
Affected Systems
Affected products include Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019, 2022, and 2025, both standard and Server Core editions, spanning x86, x64, and ARM64 architectures.
Risk and Exploitability
The CVSS score of 7 denotes a medium‑to‑high severity, while an EPSS score below 1% indicates a low likelihood of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a local authorized user interacting with the clipboard service to trigger the race condition; this can be especially hazardous in environments where untrusted local applications have clipboard access or where privileged functions are exposed to non‑admin users.
OpenCVE Enrichment