Impact
The vulnerability is a time‑of‑check time‑of‑use race condition in the Windows Win32K kernel component. It permits an authorized local user to schedule a privileged operation that bypasses normal authorization checks, enabling the escalation of privileges on the affected system. This issue is identified as CWE‑367, reflecting a concurrency flaw that results in unauthorized privilege gains.
Affected Systems
The flaw affects multiple Microsoft Windows operating systems including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server releases from 2012 through 2025 with both full and core installations.
Risk and Exploitability
The CVSS score of 7.0 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in CISA's KEV catalog. The attack vector is confined to local systems where an attacker has legitimate user access; no remote exploitation path is described. Consequently, the risk is contingent on the presence of elevated local privileges or the ability to run code with sufficient authority to trigger the race condition.
OpenCVE Enrichment