Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A race condition in Windows Runtime arises when concurrent execution accesses a shared resource without proper synchronization. The flaw can let an authorized local attacker gain higher privileges than intended, potentially compromising system integrity or enabling further attacks. The weakness is a concurrency flaw, identified as CWE-362, and may involve improper memory handling, as noted by CWE-416.

Affected Systems

The vulnerability affects Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, including Server Core installations. Users on these builds are impacted unless a fix has been applied.

Risk and Exploitability

The CVSS score of 7 indicates a high severity local privilege escalation. The EPSS score, being less than 1%, suggests a very low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation would require an attacker to have a valid local account and sufficient permissions to execute competing threads or processes to trigger the race condition, making the attack vector local.

Generated by OpenCVE AI on July 31, 2026 at 08:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest cumulative update that includes the Windows Runtime fix for 24H2, 25H2, 26H1, and Windows Server 2025.
  • Configure users with only the minimum required privileges to reduce the attack surface for local privilege escalation.
  • Review and tighten local administrator group membership and enforce User Account Control to monitor for abnormal privilege changes.

Generated by OpenCVE AI on July 31, 2026 at 08:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Title Windows Runtime Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Microsoft windows Server 2025
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1 Windows Server 2025
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:55:06.062Z

Reserved: 2026-06-04T18:15:10.953Z

Link: CVE-2026-50345

cve-icon Vulnrichment

Updated: 2026-07-15T10:50:46.477Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T08:30:03Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free