Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Key Guard allows an authorized attacker to elevate privileges locally.

Severity (CVSS)

Base score7.8
SeverityHigh
VersionCVSS 3.1
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Provided byCNA

Weaknesses

  • CWE-362 — CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Affected products

VendorProductVersions
MicrosoftWindows 10 Version 180910.0.17763.0 to <10.0.17763.9020
MicrosoftWindows 10 Version 21H210.0.19044.0 to <10.0.19044.7548
MicrosoftWindows 10 Version 22H210.0.19045.0 to <10.0.19045.7548
MicrosoftWindows 11 Version 24H210.0.26100.0 to <10.0.26100.8875
MicrosoftWindows 11 Version 25H210.0.26200.0 to <10.0.26200.8875
MicrosoftWindows 11 version 26H110.0.28000.0 to <10.0.28000.2269
MicrosoftWindows Server 201910.0.17763.0 to <10.0.17763.9020
MicrosoftWindows Server 2019 (Server Core installation)10.0.17763.0 to <10.0.17763.9020
MicrosoftWindows Server 202210.0.20348.0 to <10.0.20348.5386
MicrosoftWindows Server 202510.0.26100.0 to <10.0.26100.33158
MicrosoftWindows Server 2025 (Server Core installation)10.0.26100.0 to <10.0.26100.33158

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 15 Jul 2026 07:06 UTC.