Impact
The Windows App Store contains a race condition involving a shared resource that is improperly synchronized. A locally authorized user can exploit this flaw to interfere with normal execution flow, causing the system to grant the attacker higher privileges than intended. The result is a local privilege escalation that could give the attacker full control over the compromised machine.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 24H2, 25H2 and 26H1; Microsoft Windows Server 2016, 2019, 2022 and 2025, including their Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates a medium to high severity for local actors. However, the EPSS score is below 1%, suggesting a low probability of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and requires the attacker to be already authenticated or have physical access to the device. Once triggered, the attacker can elevate privileges to administrative levels, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment