HIGH
CVE-2025-62215
CVSS
7
KEV
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
A race condition vulnerability exists in the Windows Kernel where concurrent execution with improper synchronization allows an authorized local attacker to access shared resources incorrectly and elevate privileges to higher integrity levels.
Mitigation
Apply Microsoft security updates for this vulnerability once released. For defense-in-depth, monitor for suspicious process creation and limit local administrator privileges to reduce attack surface.
Weakness (CWE)
CWE-362
Race Condition
CWE-415
Double Free
EPSS Score
5.99%
Probability of exploitation in next 30 days
93th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.