Impact
A race condition exists in Windows Runtime that allows a concurrent attacker to exploit an improper synchronization of shared resources. The flaw can enable an unauthorized user, typically over a network, to gain elevated privileges on the affected system. The weakness is rooted in CWE-362 (Race Condition) and CWE-416 (Use After Free), both of which can break the integrity of privilege checks during simultaneous operations.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, and 22H2; Microsoft Windows 11 versions 24H2, 25H2, and 26H1; Microsoft Windows Server 2019, 2022, and 2025, including Server Core installs. No additional sub‑version filtering is provided beyond the listed major releases.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating moderate severity, yet the exploit probability reported by EPSS is only less than 1 %, and the flaw is not currently listed in the CISA KEV catalog. Attackers would need to initiate concurrent access to the Windows Runtime service from a network position, creating a timing window that triggers the race condition. While the exploit surface appears narrow and the probability low, the impact of successful elevation remains significant enough to justify prompt remediation.
OpenCVE Enrichment