Impact
The vulnerability is a race condition in the Windows Telephony Service. When two or more threads access a shared resource without proper synchronization, an attacker who already has local access can manipulate the execution order to gain higher privileges. This flaw permits local privilege escalation, allowing the attacker to elevate privileges to a level that could enable arbitrary code execution or compromise system integrity.
Affected Systems
Affected systems include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations). All listed operating systems contain the Telephony Service component that is susceptible to the race condition.
Risk and Exploitability
The CVSS score of 7 indicates a high severity, but the EPSS score is not available, making it unclear how frequently this flaw is being exploited in the wild. Since the attack vector is local and requires the attacker to be authorized on the system, the risk is significant for users who have elevated or administrative privileges. The flaw is not listed in the CISA KEV catalog, yet its absence does not reduce the urgency to patch, as the vulnerability allows a local attacker to attain high-level privileges that could lead to full system compromise.
OpenCVE Enrichment