Impact
Time‑of‑check, time‑of‑use race condition in the Windows Common Log File System Driver allows an authorized local attacker to elevate privileges on the affected Windows operating system. The vulnerability can be leveraged by an attacker who has local authentication to increase their privilege level.
Affected Systems
Affected Microsoft products include Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 23H2, 24H2, 25H2 and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022 and 2025, all editions of each release.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity. Exploitation requires a local, authenticated attacker, and EPSS Score: < 1% indicates a low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. As a result, the risk is significant for systems where local users have higher‑level access or where privilege boundaries are not strictly enforced, but it does not allow remote exploitation without an additional foothold.
OpenCVE Enrichment