Impact
The described race condition in Windows Connected User Experiences and Telemetry allows an authorized attacker to execute code with elevated privileges locally. The flaw originates from concurrent execution using a shared resource without proper synchronization, enabling manipulation of the privilege level during a legitimate user session. As a result, an attacker who can run code on the local machine may enable privileged operations that are normally restricted to administrators. This type of flaw is identified by CWE‑362 and CWE‑416, indicating improper synchronization and use-after-free vulnerabilities.
Affected Systems
Affected products include Microsoft Windows 10 versions 21H2 and 22H2, Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1, and Microsoft Windows Server 2022 and Server 2025 (including Server Core installations). These correspond to the operating system releases identified by the listed CPE strings.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The primary attack vector is local and requires an authenticated user with the ability to run code on the host. The attack requires only a race condition exploit, which can be triggered without needing network connectivity, making it a significant local threat for systems with inadequate privilege controls.
OpenCVE Enrichment