Impact
A race condition arises from improper synchronization of a shared resource in the Windows Network File System, allowing two concurrent processes to manipulate that resource in a way that can lead to arbitrary code execution. The lack of correct locking gives an attacker the ability to influence the program’s control flow, resulting in execution of malicious code on the host. The vulnerability directly affects confidentiality, integrity, and availability of the affected system if exploited.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025—including both full installs and Server Core installations. The flaw is tied to the Windows Network File System component in these releases.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1 % suggests a very low likelihood that this vulnerability will be exploited in the wild. The flaw is not listed in the CISA KEV catalog, reinforcing a lower risk profile. Based on the description, it is inferred that an attacker would need network access to the target, most plausibly via SMB traffic, to trigger the race condition and achieve code execution. No publicly disclosed exploits are mentioned in the advisory, and the low EPSS score further indicates limited real‑world activity against this flaw.
OpenCVE Enrichment