Impact
Windows Media contains a race condition involving shared resources that can be exploited by an authorized attacker to elevate privileges over a network. The flaw lies in improper synchronization when concurrent operations access the media subsystem, allowing the attacker to perform actions as a higher‑privileged user. The associated weaknesses include CWE‑362, a race condition, and CWE‑416, use‑after‑free. This can lead to execution of code with elevated rights, potentially enabling broader system compromise.
Affected Systems
Affected are Microsoft Windows 11 releases 24H2, 25H2, and 26H1, as well as Windows Server 2025, including Server Core installations. The vulnerability is present in the Windows Media component of these operating system versions.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact vulnerability, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV archive, and the attack vector is inferred to be over a network requiring the attacker to have some authorized presence. Exploitation would hinge on the attacker triggering the race condition in the media subsystem to gain elevated privileges.
OpenCVE Enrichment