Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows App Installer allows an authorized attacker to elevate privileges locally.

Severity (CVSS)

Base score7
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Provided byCNA

Weaknesses

  • CWE-362 — CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
  • CWE-416 — CWE-416: Use After Free

Affected products

VendorProductVersions
MicrosoftWindows 11 version 23H210.0.22631.0 to <10.0.22631.7376
MicrosoftWindows 11 Version 23H210.0.22631.0 to <10.0.22631.7376
MicrosoftWindows 11 Version 24H210.0.26100.0 to <10.0.26100.8875
MicrosoftWindows 11 Version 25H210.0.26200.0 to <10.0.26200.8875
MicrosoftWindows 11 version 26H110.0.28000.0 to <10.0.28000.2269
MicrosoftWindows Server 202510.0.26100.0 to <10.0.26100.33158
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0 to <10.0.26100.33158

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.