Impact
Time‑of‑check time‑of‑use race condition in the Windows kernel enables an authorized attacker to gain higher privileges locally. The flaw, classified as CWE‑367, allows a local process to manipulate kernel state before it is fully validated, providing a path to attain SYSTEM level rights.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2 and 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2 and 26H1; Microsoft Windows Server 2012 (including Server Core), 2012 R2 (including Server Core), 2016, 2019, 2022 and 2025.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate‑to‑high severity risk. No EPSS score is published, so the current exploitation probability is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a local privileged process, meaning an attacker with ordinary user rights on the machine can exploit the race condition to elevate privileges without additional network access. Given the moderate severity and lack of a public exploit, organizations should treat this as a high‑priority patchable issue for all affected Windows installations.
OpenCVE Enrichment