Impact
This vulnerability arises from a race condition in the Windows Audio Service when concurrent operations access a shared resource without proper synchronization. Because a locally authenticated user can trigger the race, the attacker can obtain higher privileges on the affected Windows 11 systems. The flaw is classified under CWE-362 and CWE-416, indicating improper synchronization and potential use-after-free bugs, and the CVSS score of 7.8 reflects its high severity.
Affected Systems
Affected are Microsoft Windows 11 24H2 and 25H2 for the arm64 architecture, and Windows 11 26H1 for the x64 architecture. These versions are enumerated by their corresponding CPE strings and are listed as vulnerable by Microsoft.
Risk and Exploitability
The EPSS score of less than 1 % suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a local user who can trigger the race condition, so the attack surface is limited to environments where the Windows Audio Service runs. Because the flaw is a local privilege escalation, potential impact includes full system compromise by an attacker who can elevate privileges. The likely attack vector is local.
OpenCVE Enrichment