Impact
Concurrent execution of Windows Installer processes that share resources without proper synchronization causes a race condition. This flaw enables an authorized local user to manipulate code execution paths, leading to elevated privileges. The underlying weakness is a classical race condition combined with a use‑after‑free error, as identified by CWE‑362 and CWE‑416.
Affected Systems
The flaw impacts multiple Microsoft Windows OS releases, including Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, and 2025, both standard and Server Core installations.
Risk and Exploitability
With a CVSS score of 7, this vulnerability poses a moderate to high risk when an attacker has local authorized access. The EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting that there is no widespread public exploitation yet. However, the local nature and requirement for an authorized user mean that the attack is likely limited to environments where such users exist, and exploitation is likely to require the attacker to run multiple installer instances simultaneously to trigger the race condition.
OpenCVE Enrichment