PT-2025-10819 · Microsoft · Windows Cross Device Service+1

John Ostrowski

·

Published

2025-03-11

·

Updated

2026-06-14

·

CVE-2025-24076

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows 11 version 22H2 Microsoft Windows versions prior to 10.0.22621.0
Description An improper access control issue exists within the Windows Cross Device Service. This allows an authorized attacker to gain elevated privileges locally. The vulnerability enables attackers to potentially affect the system and rapidly escalate to administrator privileges, with some reports indicating this can occur within 300 milliseconds. A proof-of-concept (PoC) exploit is available. The issue stems from flaws in access control within the Cross Device Service.
Recommendations Microsoft Windows 11 version 22H2: Update to version 10.0.22621.0 or later. Microsoft Windows versions prior to 10.0.22621.0: Update to the latest available version.

Exploit

Fix

LPE

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02565
BDU:2025-02713
CVE-2025-24076

Affected Products

Windows
Windows Cross Device Service