Impact
Concurrent execution using the Windows Telephony Service with improper synchronization causes a race condition and a use‑after‑free flaw. An attacker who has local access and sufficient permissions can trigger the defect to gain higher privileges on the affected system. The vulnerability does not provide a path to remote code execution or denial of service; it focuses on local privilege elevation.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 in both full and server‑core installations.
Risk and Exploitability
The CVSS score of 7 indicates a high severity and the EPSS score is < 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog, implying no known public exploits. The attack would require a legitimate local user account and the ability to invoke the Telephony Service; once triggered the attacker can obtain expanded privileges. Given the high local privilege impact, the risk to affected systems is significant for environments where local accounts are not tightly controlled.
OpenCVE Enrichment