Impact
A race condition in the Windows Win32K subsystem allows a local, authorized attacker to gain elevated privileges by exploiting improper synchronization of a shared resource. The flaw qualifies as a classic race condition (CWE-362).
Affected Systems
Microsoft Windows 10 releases 1607, 1809, 21H2, and 22H2; Windows 11 releases 24H2, 25H2, and 26H1; and all Windows Server releases from 2012 through 2025, including 2012 R2, 2016, 2019, 2022, and 2025, with all Server Core installations, are affected.
Risk and Exploitability
The CVSS score is 8.8, indicating a high severity. The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low probability of widespread exploitation. The description indicates that the vulnerability requires local access; the attacker would need to trigger the race condition during concurrent processing within Win32K. Based on the description, it is inferred that an exploit would rely on a precise timing window and an authorized local user. While the CVE does not provide details about successful exploitation, the narrow timing requirement may reduce the likelihood of successful attacks in typical environments.
OpenCVE Enrichment