Impact
A race condition exists in the Windows Key Guard component that occurs when multiple privileged and non‑privileged processes execute concurrent operations on a shared resource. Because the component does not synchronize access to a critical data structure, an attacker can manipulate the order of operations to cause the system to treat a non‑privileged request as privileged. This flaw, classified as CWE-362, gives an authorized local user the ability to gain higher privileges and perform actions normally reserved for system or administrator accounts.
Affected Systems
The vulnerability affects Microsoft Windows OS and server editions that ship the Key Guard service, including Windows 10 Version 1809, 21H2, 22H2; Windows 11 Version 24H2, 25H2, 26H1; Windows Server 2019 (full installation and Server Core); Windows Server 2022; and Windows Server 2025 (full installation and Server Core). All affected editions are documented in the Microsoft Security Update Guide under CVE‑2026‑50378.
Risk and Exploitability
The CVSS base score of 7.8 indicates high severity, but the EPSS score of less than 1 % suggests exploitation is unlikely at present. Since the flaw is not listed in CISA’s KEV catalog, there is no known large‑scale exploitation. However, the local nature of the attack means an attacker who can execute code or commands on the system can potentially raise privileges and impact the confidentiality, integrity, and availability of that machine.
OpenCVE Enrichment