Microsoft Windows Subsystem for Linux
cpe:2.3:a:microsoft:windows_subsystem_for_linux:*:*:*:*:*:*:*
A time-of-check time-of-use (TOCTOU) race condition vulnerability has been identified in the Windows Subsystem for Linux (WSL2) kernel. This vulnerability allows an authorized attacker to locally elevate privileges to the SYSTEM level. The issue arises from the nature of the race condition, where the timing of events can be manipulated to create a vulnerability.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can apply the official security update available through the Microsoft Update Catalog. For more details, refer to the WSL release notes on GitHub.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.