Impact
A race condition exists in the Windows USB Print Driver due to improper synchronization of a shared resource. When two or more execution paths collide, an attacker who can trigger concurrent access can manipulate the driver’s state to elevate privileges, gaining administrative‑level rights or executing arbitrary code on the local system.
Affected Systems
The flaw affects Microsoft Windows 11 versions 24H2, 25H2, and 26H1, as well as Windows Server 2025, including its Server Core installation. These specific editions are explicitly listed by Microsoft as vulnerable.
Risk and Exploitability
The CVSS score of 7.8 marks the issue as high severity, yet the EPSS score of less than 1% indicates that exploitation is currently considered unlikely. The vulnerability is not present in the CISA KEV catalog, so no confirmed public exploits exist. The required attack vector is inferred to be local, needing an attacker with authorized access or physical presence to manipulate the USB driver in a way that triggers the race condition.
OpenCVE Enrichment