Impact
The vulnerability arises from a race condition in the Windows Bind Filter Driver when multiple threads access a shared resource concurrently. An authorized local user can exploit this flaw to acquire higher privileges on the affected system, potentially reaching SYSTEM or administrative rights, thereby compromising confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 11 24H2 on ARM64, Microsoft Windows 11 25H2 on ARM64, and Microsoft Windows 11 26H1 on x64 are affected. Other Windows 11 releases and architectures are not listed as vulnerable.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. No EPSS information is currently available and the vulnerability is not listed in the CISA KEV catalog, implying that no widespread exploitation is known. The likely attack vector involves a local authorized user triggering the race condition through concurrent operations on the Bind Filter Driver. Because the flaw requires local privilege and race timing, the exploitation effort is non‑trivial but within reach of skilled attackers.
OpenCVE Enrichment