Impact
The vulnerability is a time‑of‑check time‑of‑use race condition in the Windows MIDI Service Module. An authorized local user can exploit the race to perform a privilege‑escalation attack, potentially gaining higher privileges such as SYSTEM. The flaw is categorized as a race condition (CWE‑367) and allows escalation only on the local system where the attacker has sufficient access to trigger the race.
Affected Systems
The affected products are Microsoft Windows 11 Version 24H2, Version 25H2, and Version 26H1. According to the common platform enumeration, the first two releases target the arm64 architecture, while Version 26H1 targets x64. No specific sub‑version details were provided beyond these release labels.
Risk and Exploitability
The CVSS score of 7.0 indicates a high severity, but the flaw is limited to a local privilege escalation scenario. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local; an attacker who can execute code or commands on the target machine can trigger the race condition and elevate privileges. Due to the local nature, this risk is mitigated by restricting local user privileges and ensuring the service runs only when necessary.
OpenCVE Enrichment