PT-2025-46508 · Microsoft · Windows Kernel +1

Published

2025-11-11

·

Updated

2025-11-30

·

CVE-2025-62215

CVSS v3.1
7.0
VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to November 2025 Patch Tuesday
Description A race condition exists within the Windows Kernel, allowing a locally authorized attacker to elevate privileges. This issue, actively exploited in the wild, involves improper synchronization when accessing shared resources. Successful exploitation requires an attacker to win a race condition, potentially granting them SYSTEM-level privileges. Reports indicate that threat actors are already weaponizing this flaw. Approximately 31 articles from various internet sources have been published regarding this vulnerability, highlighting its significance. The vulnerability allows attackers to manipulate memory management, potentially leading to kernel heap corruption and hijacking system execution flow.
Recommendations Apply the November 2025 Patch Tuesday updates immediately to all affected systems.

Fix

LPE

RCE

Race Condition

Double Free

Weakness Enumeration

Related Identifiers

BDU:2025-14039
CVE-2025-62215

Affected Products

Windows
Windows Kernel