Impact
The vulnerability is a race condition in the Windows Telephony Service where concurrent access to shared resources is not properly synchronized. This flaw permits a local user with sufficient permissions to manipulate the service’s execution flow and ultimately gain higher privilege levels. The primary impact is privilege escalation, as an attacker can elevate their own privileges to match those of the service, potentially allowing further exploitation on the system.
Affected Systems
The flaw affects multiple Microsoft Windows releases, including Windows 10 versions 1607, 1809, 21H2 and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, and the corresponding ARM64 builds, as well as Windows Server 2012, 2012 R2, 2016, 2019, 2022 and 2025 in both full and Server Core images. No additional version granularity or patches are specified in the current CNA data.
Risk and Exploitability
With a CVSS score of 7.0 the vulnerability falls within the moderate severity range. The exploitation probability is unclear because no EPSS score is available, and the issue is not listed in CISA’s KEV catalog. The attack requires local, authorized access to the affected machine and relies on triggering a race condition, so the risk is considered moderate compared to remote or zero‑day exploits. Nonetheless, any local attacker who succeeds can gain privilege escalation, which is inherently risky.
OpenCVE Enrichment