Impact
The vulnerability is a race condition in the Windows TCP/IP stack that allows an attacker with local access to manipulate a shared resource. When the improper synchronization is exploited, the attacker can gain elevated privileges on the system, potentially obtaining administrative control. This flaw is classified as CWE‑362 and CWE‑416, indicating concurrent execution bugs and use‑after‑free errors.
Affected Systems
Affected are Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, including both full and server‑core installations.
Risk and Exploitability
The CVSS base score of 7 denotes a high‑severity flaw that could be exploited locally. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. An authorized local attacker would need to trigger a specific timing and scheduling scenario in the TCP/IP stack; no public exploit is currently documented. Despite the lack of a known exploit, the potential to elevate privileges makes this a significant risk in environments where privileged accounts are at risk.
OpenCVE Enrichment