Impact
The Windows Runtime component contains a race condition caused by improper synchronization of a shared resource. An attacker with local, authorized access can trigger this condition to elevate privileges. The vulnerability is classified as CWE‑362 and includes aspects associated with CWE‑416. Successful exploitation results in local privilege escalation, enabling the attacker to perform actions normally reserved for privileged users.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Microsoft Windows Server 2025 and its Server Core installation, are impacted by the race condition in the Windows Runtime. No other vendors or products are documented as affected.
Risk and Exploitability
The CVSS score of 7 combined with an EPSS score of less than 1% indicates that exploitation is considered unlikely at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local, authorized user who can trigger the race condition via the Windows Runtime API; there is no known remote attack vector. The risk remains significant in environments where privileged users may run untrusted or poorly controlled code, but exposure is limited to local systems.
OpenCVE Enrichment