Impact
A race condition in the Windows Telephony Service allows an authenticated local user to exploit unsynchronized concurrent access to a shared resource, leading to a privilege escalation. The flaw originates from improper handling of race conditions (CWE‑362) and a use‑after‑free bug (CWE‑416), granting the attacker control over privileged operations within the service.
Affected Systems
Microsoft Windows 10 1607, 1809, 21H2, 22H2; Microsoft Windows 11 23H2, 24H2, 25H2, 26H1 and an additional 23H2 variant; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 including Server Core deployments. All affected systems run the Telephony Service component.
Risk and Exploitability
The CVSS score of 7 indicates medium‑to‑high severity. The EPSS score of < 1% indicates a very low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread public exploitation has been reported. The flaw can be leveraged by an authenticated local user to trigger concurrent access to a shared resource in the Telephony Service, enabling local privilege escalation. No additional privileges or conditions beyond those required to run the Telephony Service are necessary.
OpenCVE Enrichment