Impact
A race condition in Windows Operating System’s handling of a shared resource permits an authorized local user to gain higher privileges. The flaw stems from improper synchronization when concurrent operations access the same resource, allowing a privileged attacker to trigger privileged code paths that elevate the attacker’s rights. This results in an attacker who can perform tasks beyond their originally granted rights, potentially compromising system integrity.
Affected Systems
Windows 11 Version 24H2, Windows 11 Version 25H2, Windows 11 Version 26H1, Windows Server 2025 and Server Core installations. These include ARM64 and x64 builds as specified by Microsoft’s updates.
Risk and Exploitability
The CVSS score of 7.8 signals a high severity Windows vulnerability, yet the EPSS of < 1% indicates a very low current exploitation probability. It is not listed in the CISA KEV catalog. The attack requires local access to the target machine; an authorized user can trigger the race condition to gain higher privileges. Once elevated, the attacker can fully compromise the system.
OpenCVE Enrichment