CVE-2026-21221EPSS p13.0%

CVE-2026-21221CVE-2026-21221

microsoft / windows_11_24h2

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an authorized attacker to elevate privileges locally.

Scoring

CVSS 7.0 ()
VectorCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.23% probability of exploitation · percentile 13.0% · 2026-10-05T12:00:23Z
Last modified2026-07-30
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.