Impact
This vulnerability is a race condition in the Windows Wireless Wide Area Network Service caused by improper synchronization of a shared resource. The flaw can be exploited by an attacker who already has authorized local access to hijack execution flow and elevate privileges. The weakness is identified as CWE-362, meaning an attacker can manipulate timing to compromise integrity and authenticity of operations. The resulting impact is that the attacker can run code with higher privileges, potentially gaining system control, modifying system files, and establishing persistent footholds.
Affected Systems
Affected products include Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 24H2, 25H2, 26H1; and Microsoft Windows Server 2019, 2019 Server Core, 2022, 2025, and 2025 Server Core installations.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability. However, the EPSS score is below 1%, implying a very low likelihood of exploitation in the wild at the time of analysis. The flaw is not listed in the CISA KEV catalog. A local attacker with authorized access is the inferred attack vector, as the service can be triggered without remote interaction. Successful exploitation requires precise timing to manipulate the shared resource during concurrent execution.
OpenCVE Enrichment