Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in the Windows kernel arises from improper synchronization of a shared resource, allowing an attacker with local or authorized access to manipulate kernel scheduling or memory reuse and bypass permission checks, thereby elevating privileges to SYSTEM level. This flaw is characterized by the weaknesses detailed in CWE-362 and CWE-416, exposing the kernel to unauthorized access and potentially enabling full control of the affected system.

Affected Systems

The vulnerability targets Microsoft Windows 11 releases 24H2, 25H2, 26H1 and Microsoft Windows Server 2025, including its Server Core installation. Versions 24H2 and 25H2 run on ARM64, while 26H1 runs on x64.

Risk and Exploitability

The CVSS base score of 7.8 indicates high severity, yet the EPSS score of less than 1 % reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation currently. Attackers must have local privileges, thus the vector is considered local. Despite the low exploitation probability, the impact remains significant, warranting prompt remediation to prevent privilege escalation by an authorized local adversary.

Generated by OpenCVE AI on July 31, 2026 at 08:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the cumulative Windows update supplied by Microsoft that includes the kernel race condition fix for Windows 11 24H2, 25H2, 26H1 and Windows Server 2025.
  • If Windows Update is unavailable, download the relevant update package directly from the Microsoft Security Update Guide and install it manually.
  • Configure local accounts with least privilege and keep User Account Control enabled to limit the potential impact of residual kernel vulnerabilities.

Generated by OpenCVE AI on July 31, 2026 at 08:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Title Windows Kernel Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:54:32.230Z

Reserved: 2026-06-01T17:02:37.208Z

Link: CVE-2026-49808

cve-icon Vulnrichment

Updated: 2026-07-15T11:05:05.867Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:00:07Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free