CVE-2025-62215
Microsoft · Published November 11, 2025
7.0
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 10 1809 < 10.0.17763.8027
- Windows 10 21h2 < 10.0.19044.6575
- Windows 10 22h2 < 10.0.19045.6575
- Windows 11 23h2 < 10.0.22631.6199
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H