Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Windows Media is a race condition that occurs when multiple operations access a shared resource without proper synchronization. This concurrency bug allows a local user who is already authorized to execute code within Windows Media to elevate their privileges. The vulnerability is identified as CWE‑362 and may also involve a use‑after‑free scenario (CWE‑416). Successfully exploiting the race condition would grant the attacker administrative rights, enabling them to modify files, install software, or maintain persistence on the system.

Affected Systems

The affected releases are Microsoft Windows 11 version 24H2 for ARM64, version 25H2 for ARM64, and version 26H1 for x64. These are the only builds explicitly indicated as vulnerable in the advisory.

Risk and Exploitability

The CVSS base score is 7.8, placing the issue in the high severity range. The EPSS score is less than 1 %, indicating that, although the exploit is very unlikely to be observed in practice, the potential for local privilege escalation still exists. The vulnerability is not listed in the CISA KEV catalog, and no widespread exploitation has been reported. The required conditions include a local, authorized user account and execution of Windows Media; no network or remote execution vector is described.

Generated by OpenCVE AI on July 31, 2026 at 07:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Windows 11 cumulative update that contains the Windows Media race condition fix.
  • Disable or uninstall Windows Media components on accounts that do not require media playback to reduce the attack surface.
  • Monitor Windows event logs for privilege‑escalation attempts and keep security advisories from Microsoft up to date.

Generated by OpenCVE AI on July 31, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Description Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Media allows an authorized attacker to elevate privileges locally.
Title Windows Media Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
Weaknesses CWE-362
CWE-416
CPEs cpe:2.3:o:microsoft:windows_11_24H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_25H2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_26H1:*:*:*:*:*:*:x64:*
Vendors & Products Microsoft
Microsoft windows 11 24h2
Microsoft windows 11 25h2
Microsoft windows 11 26h1
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows 11 24h2 Windows 11 25h2 Windows 11 26h1
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-07-30T20:25:47.069Z

Reserved: 2026-06-05T14:35:07.079Z

Link: CVE-2026-50676

cve-icon Vulnrichment

Updated: 2026-07-15T10:45:32.947Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T07:30:04Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-416

    Use After Free