Impact
A race condition in the Windows Runtime allows an authorized local user to trigger concurrent operations on a shared resource. The improper synchronisation of that resource enables the operating system to grant higher privileges during a conflict, allowing the attacker to run code with authority beyond what is normally permitted.
Affected Systems
Microsoft Windows 11 24H2, 25H2, and 26H1, as well as Windows Server 2022 and Windows Server 2025—including Server Core installations—are affected. The issue appears in ARM64 builds for 24H2 and 25H2 and in the x64 build for 26H1.
Risk and Exploitability
The flaw carries a CVSS score of 7.8, indicating high severity, but the EPSS score is below 1 %, suggesting that exploitation is currently unlikely. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is local and requires an authorized user to run code within the Windows Runtime environment to induce the race condition; no remote exploitation pathway is described in the available data.
OpenCVE Enrichment