Impact
Concurrent execution using shared resources with improper synchronization in the Windows USB Print The flaw is a race condition that can result in the attacker gaining higher local privileges on the affected machine.
Affected Systems
Microsoft Windows 11 versions 24H2, 25H2, and 26H1, and Windows Server 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. The EPSS score of <1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalogue. Likely exploitation requires the attacker to have local or authorized access to the system, as the flaw is a local race condition. When the race condition is triggered, the attacker can obtain elevated local privileges.
OpenCVE Enrichment