Zero-day vulnerability in Windows

Race condition
CVE-2025-62215

Vulnerability details

Advisory: SB2025111168 - Privilege escalation in Microsoft Windows kernel

Vulnerable component: Windows

CVE-ID: CVE-2025-62215

CVSSv3 score: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-362 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

Description:

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a race condition within the OS kernel. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.

Note, the vulnerability is being actively exploited in the wild.

External links:

https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2025-62215