Impact
The flaw in Windows Media is a race condition that occurs when multiple operations access a shared resource without proper synchronization. This concurrency bug allows a local user who is already authorized to execute code within Windows Media to elevate their privileges. The vulnerability is identified as CWE‑362 and may also involve a use‑after‑free scenario (CWE‑416). Successfully exploiting the race condition would grant the attacker administrative rights, enabling them to modify files, install software, or maintain persistence on the system.
Affected Systems
The affected releases are Microsoft Windows 11 version 24H2 for ARM64, version 25H2 for ARM64, and version 26H1 for x64. These are the only builds explicitly indicated as vulnerable in the advisory.
Risk and Exploitability
The CVSS base score is 7.8, placing the issue in the high severity range. The EPSS score is less than 1 %, indicating that, although the exploit is very unlikely to be observed in practice, the potential for local privilege escalation still exists. The vulnerability is not listed in the CISA KEV catalog, and no widespread exploitation has been reported. The required conditions include a local, authorized user account and execution of Windows Media; no network or remote execution vector is described.
OpenCVE Enrichment