HIGH

CVE-2025-62215

Microsoft Windows 10 1809 2025-11-11 CVSS v3.1
CVSS
7
KEV

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A race condition vulnerability exists in the Windows Kernel where concurrent execution with improper synchronization allows an authorized local attacker to access shared resources incorrectly and elevate privileges to higher integrity levels.

Mitigation

Apply Microsoft security updates for this vulnerability once released. For defense-in-depth, monitor for suspicious process creation and limit local administrator privileges to reduce attack surface.

Weakness (CWE)

CWE-362 Race Condition
CWE-415 Double Free

EPSS Score

5.99%
Probability of exploitation in next 30 days
93th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE