Impact
Concurrent execution using a shared resource within the Windows Backup Engine, without proper synchronization, introduces a race condition that an authorized local attacker can exploit to gain elevated privileges on the affected system. The flaw arises from improper handling of shared resources, allowing the attacker to manipulate execution order and gain kernel-level authority, potentially compromising system confidentiality, integrity, and availability.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including server core installations. All listed installations of the Windows Backup Engine are impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7, indicating moderate to high severity, but the EPSS score is below 1%, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog. The likely attack vector is a local privileged user taking advantage of the race condition to execute code with elevated rights. No publicly disclosed exploit code is demonstrated, and the flaw requires that the attacker already has authorization to run the Backup Engine service.
OpenCVE Enrichment