Impact
A concurrent execution race condition in the Windows Backup Engine enables an authorized local user to gain system privileges. The flaw arises from improper synchronization of shared resources and can lead to full control of the affected machine, compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 Version 21H2 (x86), Windows 10 Version 22H2 (x64), Windows 11 Version 24H2 (arm64), Windows 11 Version 25H2 (arm64), and Windows 11 Version 26H1 (x64).
Risk and Exploitability
The CVSS score of 7 indicates a moderately high impact, while an EPSS score of < 1% shows a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning no known exploits are publicly documented. The attack vector is inferred to be local: an attacker who already has some level of local authorization can trigger the race condition to elevate privileges.
OpenCVE Enrichment