Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A time-of-check time-of-use (TOCTOU) race condition has been identified in the Windows Local Security Authority (LSA). This vulnerability allows an authorized attacker to elevate privileges locally. The issue arises from the nature of the race condition, where the timing of events can be manipulated to gain unauthorized access to higher privileges.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Security updates addressing this vulnerability are available for various Windows versions, including Windows 10, Windows Server 2012, Windows Server 2008 R2, Windows Server 2016, and Windows 11. Specific update details can be found in the Microsoft Knowledge Base articles referenced in the security update guide.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.