Microsoft Windows Subsystem for Linux Privilege Escalation Vulnerability

Vulnerability

A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the Windows Subsystem for Linux (WSL2) kernel. This vulnerability allows an authorized attacker to locally elevate privileges to the SYSTEM level. The issue arises from the nature of the race condition, where the timing of events can be manipulated to create a vulnerability.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.

Remediation

Users can apply the official security update available through the Microsoft Update Catalog. For more details, refer to the WSL release notes on GitHub.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
6.6
impact
7.5
exploitability
2.9
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.