Impact
Time‑of‑check, time‑of‑use race condition in the Windows Subsystem for Linux 2 (WSL2) kernel enables an authorized local attacker to modify kernel code or data before it is used. The flaw, identified as CWE‑367, can alter kernel components, potentially compromising the integrity of the kernel and the confidentiality of data running under WSL2. The description states that the attacker must have authorized access, indicating the vulnerability is exploitable only from the local machine.
Affected Systems
Microsoft Windows Subsystem for Linux 2 (WSL2) is impacted. No specific product or version numbers are provided, so all current releases of WSL2 are presumed affected until an update is applied.
Risk and Exploitability
The CVSS score of 6.3 classifies the vulnerability as moderate severity, while the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local, requiring an authorized user to trigger the race condition within the kernel verification process; consequently, the threat is confined to machines where the attacker has sufficient local privileges.
OpenCVE Enrichment