Impact
The vulnerability is a race condition in the Windows Management Instrumentation (WMI) component that arises when shared resources lack proper synchronization. Authorized users with local access can exploit this condition to gain elevated privileges. The flaw maps to CWE‑362 and CWE‑416, indicating improper synchronization and use‑after‑free vulnerabilities.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Microsoft Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, and 2025 (including Server Core installations).
Risk and Exploitability
The CVSS score of 6.4 classifies this as a moderate‑severity vulnerability. EPSS is not available, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed weaponized exploitation. Based on the description, the attack vector is likely local; an attacker with legitimate user privileges on a target machine would need to orchestrate concurrent operations that trigger the race condition in WMI to elevate privileges. No special network access or elevated privileges are required beyond those of the authorized user, making the threat surface significant for any environment where WMI is enabled and users can execute code on the local system.
OpenCVE Enrichment