PT-2025-10819 · Microsoft · Windows Cross Device Service+1
John Ostrowski
·
Published
2025-03-11
·
Updated
2026-06-14
·
CVE-2025-24076
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 11 version 22H2
Microsoft Windows versions prior to 10.0.22621.0
Description
An improper access control issue exists within the Windows Cross Device Service. This allows an authorized attacker to gain elevated privileges locally. The vulnerability enables attackers to potentially affect the system and rapidly escalate to administrator privileges, with some reports indicating this can occur within 300 milliseconds. A proof-of-concept (PoC) exploit is available. The issue stems from flaws in access control within the Cross Device Service.
Recommendations
Microsoft Windows 11 version 22H2: Update to version 10.0.22621.0 or later.
Microsoft Windows versions prior to 10.0.22621.0: Update to the latest available version.
Exploit
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows Cross Device Service