Impact
Concurrent execution of Windows Runtime components that share a resource can cause a race condition due to improper synchronization. An attacker who already has some local authority can exploit this race condition to raise privileges, achieving local privilege escalation.
Affected Systems
Systems running Microsoft Windows 11 version 24H2, 25H2 or 26H1, and Microsoft Windows Server 2025—including Server Core installations—are vulnerable. The ARM64 builds of Windows 11 24H2 and 25H2, the x64 build of Windows 11 26H1, and all builds of Windows Server 2025 contain the affected runtime.
Risk and Exploitability
The CVSS score of 7 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in CISA’s KEV catalog. An attacker would need local authorized access to trigger the race condition; no remote attack vector is described.
OpenCVE Enrichment