Impact
The flaw is a race condition in the Windows Event Logging Service that permits an authorized local user to gain higher privileges. The vulnerability stems from improper synchronization of a shared resource, described as CWE‑362. An attacker with local access could execute privileged operations that normally require administrative authority, potentially compromising system integrity and confidentiality. The impact is confined to the host machine and does not allow denial of service or remote code execution.
Affected Systems
Microsoft Windows 10 versions 21H2 and 22H2, Microsoft Windows 11 versions 23H2 through 26H1 (both x64 and ARM64 architectures), and Microsoft Windows Server 2022 and 2025—including Server Core installations—are affected.
Risk and Exploitability
The CVSS score of 7 indicates a medium‑to‑high severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not currently exploited in the wild. The attack vector is local, requiring the attacker to have privileged access or to abuse existing user credentials. Exploitation would involve manipulating the timing of concurrent operations within the Event Logging Service, a scenario that typically demands elevated privileges to maintain persistence or further compromise.
OpenCVE Enrichment