Impact
The vulnerability is a race condition in the Windows NTFS file system that can be exploited by an authorized local user to gain higher privileges. By concurrently accessing a shared resource in the file system, an attacker can corrupt the normal synchronization mechanism and perform actions normally disallowed by their current privilege level. This allows the attacker to elevate privileges locally on the affected machine. The weakness is a classic concurrency issue (CWE-362).
Affected Systems
The flaw affects multiple versions of Microsoft Windows. The impacted releases include Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (24H2, 25H2, 26H1) and several Windows Server editions: Server 2012, Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025, with both full and Server Core installations listed.
Risk and Exploitability
The CVSS score of 7.8 classifies the vulnerability as high severity, while the EPSS score of 2% indicates a low but noticeable probability of exploitation. It is not present in the CISA KEV catalog. Attackers must have local authorized access and be able to orchestrate simultaneous file‑system operations to trigger the race condition, and no remote network access is required. The attack vector is therefore local and needs privilege or local access to the affected system.
OpenCVE Enrichment