PT-2025-46508 · Microsoft · Windows Kernel +1

Published

2025-11-11

·

Updated

2026-01-17

·

CVE-2025-62215

CVSS v3.1
7.0
VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows (affected versions not specified)
Description A race condition exists within the Windows Kernel, allowing an authorized attacker with local access to elevate privileges. This issue is actively exploited and has been identified as a zero-day vulnerability. Successful exploitation involves winning a race condition, potentially granting the attacker SYSTEM-level privileges. The vulnerability stems from improper synchronization when accessing shared resources, specifically a double free condition. This flaw could allow attackers to hijack system execution flow and gain complete control of the system. Reports indicate that this vulnerability is being actively weaponized by threat actors. Approximately 31 articles have been published regarding this vulnerability from various internet sources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

LPE

Race Condition

Double Free

Weakness Enumeration

Related Identifiers

BDU:2025-14039
CVE-2025-62215

Affected Products

Windows
Windows Kernel