Impact
A race condition in the Windows USB Print Driver allows an attacker who already has authorized access to the system to gain higher privileges. The flaw is caused by improper synchronization on a shared resource, described by CWE‑362, and is also associated with a use‑after‑free issue (CWE‑416). Exploiting the concurrency error could enable the attacker to execute code with elevated rights, potentially permitting the installation of software or alteration of system‑level configurations. The impact is limited to the privileges of the account that performed the action once the race condition is triggered.
Affected Systems
Microsoft Windows 11 24H2, 25H2, and 26H1, including ARM64 builds for 24H2 and 25H2 and the x64 build for 26H1, as well as Windows Server 2025 and its Server Core installation are affected. The vulnerability exists in the Universal Print Service and the Windows USB Print Driver across the listed architectures.
Risk and Exploitability
The CVSS score of 6.3 indicates a moderate severity rating, while the EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog and no active exploits are publicly reported. An attacker would need authorized access to the system and physical access to a USB‑connected printer or similar device to trigger the race condition in the print service, so the overall risk remains moderate and the exploitation vector is constrained.
OpenCVE Enrichment