← Voltar para CVEs
CVE-2025-62215
HIGHCISA KEV7.0
Descricao
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Detalhes CVE
Pontuacao CVSS v3.17.0
SeveridadeHIGH
Vetor CVSSCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vetor de ataqueLOCAL
ComplexidadeHIGH
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado11/11/2025
Ultima modificacao11/14/2025
Fontekev
Avistamentos honeypot0
CISA KEV
FornecedorMicrosoft
ProdutoWindows
Nome da vulnerabilidadeMicrosoft Windows Race Condition Vulnerability
Data inclusao KEV2025-11-12
Prazo de remediacao2025-12-03
Uso em ransomwareUnknown
Produtos afetados
microsoft:windows_10_1809microsoft:windows_10_21h2microsoft:windows_10_22h2microsoft:windows_11_23h2microsoft:windows_11_24h2microsoft:windows_11_25h2microsoft:windows_server_2019microsoft:windows_server_2022microsoft:windows_server_2022_23h2microsoft:windows_server_2025
Fraquezas (CWE)
CWE-362CWE-415
Referencias
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62215(secure@microsoft.com)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62215(134c704f-9b21-4f2e-91b3-4a467353bcc0)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.