Executive brief
Windows Backup Engine is a core component of Windows that protects critical data by creating scheduled backups. A race condition in the backup engine allows a local attacker with existing system access to elevate their privileges, potentially gaining administrator-level control and access to all protected data and system functions.
Technical details
This vulnerability is a race condition (CWE-362) in the Windows Backup Engine's resource synchronization. An authorized local attacker can exploit improper synchronization of shared resources during concurrent execution to escalate privileges. The vulnerability requires local access and is not remotely exploitable; it does not require user interaction. A successful exploit grants the attacker elevated privileges on the affected system. Microsoft has issued security patches to resolve this issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-08-11: disclosed