Impact
The vulnerability is a race condition in the Windows USB Print Driver caused by improper synchronization of a shared resource. An authorized local user who can trigger concurrent operations against the driver may manipulate privileged actions, allowing them to elevate privileges on the affected system. This weakness is identified as CWE‑362 and CWE‑416.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025—including Server Core installations—are impacted. Versions 24H2 and 25H2 are available only for arm64, while 26H1 is available only for x64. The listed CPE entries confirm these builds.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, but the EPSS score of less than 1% suggests a very low likelihood of widespread exploitation at the time of analysis. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a local attacker with authorized access to a system running the affected driver and relies on a timing attack that triggers the race condition. Remote exploitation is not described. Mitigation thus focuses on applying the vendor patch and limiting USB printing activity to reduce exposure.
OpenCVE Enrichment