Impact
The vulnerability is a race condition that occurs when multiple processes concurrently use shared resources in the Windows MIDI Service Module. Improper synchronization allows an attacker who already has local access to the system to obtain higher privileges. The flaw involves a typical race condition and results in a local elevation of privilege, potentially giving the attacker full control over the affected device.
Affected Systems
The flaw affects Windows 11 versions 24H2, 25H2, and 26H1 on both ARM64 and x64 architectures, as reflected by the corresponding CPE entries for these releases. Affected users are those running these specific builds of Windows 11.
Risk and Exploitability
The CVSS score of 7 indicates a high severity. No EPSS value is available, and the flaw is not listed in the CISA KEV catalog. The expected attack vector is local: it requires an authorized user to trigger a race condition in the system service, so an attacker would need to execute code on the machine. Given the local nature of the attack, the primary impact is a compromise of the system owner's privileges, without remote exploitation.
OpenCVE Enrichment