PT-2025-1220 · Microsoft · Windows Recovery Environment Agent+1

Published

2025-01-14

·

Updated

2026-01-11

·

CVE-2025-21202

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Windows (affected versions not specified)
Description An elevation-of-privilege issue exists within the Windows Recovery Environment Agent component. Successful exploitation of this issue could allow an attacker to gain elevated privileges on the system. The issue is related to access control errors.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2025-00599
CVE-2025-21202

Affected Products

Windows
Windows Recovery Environment Agent