Impact
A race condition in the Windows kernel arises from improper synchronization of a shared resource, allowing an attacker with local or authorized access to manipulate kernel scheduling or memory reuse and bypass permission checks, thereby elevating privileges to SYSTEM level. This flaw is characterized by the weaknesses detailed in CWE-362 and CWE-416, exposing the kernel to unauthorized access and potentially enabling full control of the affected system.
Affected Systems
The vulnerability targets Microsoft Windows 11 releases 24H2, 25H2, 26H1 and Microsoft Windows Server 2025, including its Server Core installation. Versions 24H2 and 25H2 run on ARM64, while 26H1 runs on x64.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, yet the EPSS score of less than 1 % reflects a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying no widespread exploitation currently. Attackers must have local privileges, thus the vector is considered local. Despite the low exploitation probability, the impact remains significant, warranting prompt remediation to prevent privilege escalation by an authorized local adversary.
OpenCVE Enrichment