Impact
A race condition in Windows Wireless Networking allows an authorized local user to raise privileges, potentially enabling compromise of system controls and data. The flaw, classified as CWE-362, arises from concurrent execution of shared resources without proper synchronization. Exploiting this vulnerability can result in execution of code with higher rights than the user’s current profile.
Affected Systems
Affected are Microsoft Windows 10 versions 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server 2019 (including Server Core), 2022, and 2025 (including Server Core) builds.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, however the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, and the attack vector is local, requiring an authorized attacker to trigger concurrent access to the wireless networking components.
OpenCVE Enrichment