Executive brief
A security vulnerability exists in the Microsoft Windows Capability Access Management Service, which manages how applications access hardware features like cameras or microphones. An attacker who already has basic access to a computer could exploit this flaw to gain higher-level administrative privileges. This could allow them to take full control of the system, access sensitive data, or bypass security protections.
Technical details
A race condition (CWE-362) exists in the Capability Access Management Service (camsvc) due to improper synchronization when accessing shared resources. The vulnerability requires the attacker to have local access to the system with low-level privileges. By successfully exploiting the timing of concurrent executions, an attacker can achieve local privilege escalation (LPE), gaining SYSTEM-level access or similar high-integrity permissions. The attack complexity is rated as high, likely due to the precise timing required to win the race condition. Microsoft has released security updates to address this issue across affected Windows 11 and Windows Server 2025 versions.
Affected products
- Microsoft Windows 11 Version 24H2 Up to 10.0.26100.7623
- Microsoft Windows 11 Version 25H2 Up to 10.0.26200.7623
- Microsoft Windows Server 2025 Up to 10.0.26100.32230
Timeline
- 2026-01-13: disclosed
- 2026-01-13: advisory