Impact
The vulnerability arises from a race condition in the Windows AppX Deployment Service, caused by improper synchronization when multiple processes concurrently access a shared resource, allowing an authorized local attacker to elevate privileges and potentially gain administrative rights. The weakness is classified as CWE‑362, a typical race condition that can be exploited to bypass intended access controls.
Affected Systems
Affected Microsoft Windows operating systems include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1), and Windows Server ranging from Server 2012 through Server 2025, including Server Core installations. The flaw applies to both standard and Server Core installations, affecting x86, x64, and ARM64 architectures as detailed in the vulnerability data.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at this time. The vulnerability is not yet listed in the CISA KEV catalog. Exploitation requires the attacker to be authenticated and able to run code; the attack vector is local. Because the flaw hinges on a race condition, a successful exploit would likely involve carefully timed operations that must occur during concurrent service activity.
OpenCVE Enrichment