ZeroHour

CVE-2025-62215

KEVmass1

Local Privilege Escalation via Race Condition in Microsoft Windows Kernel

CISA: Microsoft Windows Race Condition Vulnerability

CVSS 3.1
7.0 high
EPSS
6%p93
Published
()
KEV added
AI analysis

A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed.

What to do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available.

Affected
microsoft Windows 101809 (builds prior to the November 2025 security updates)
microsoft Windows 1021H2 (builds prior to the November 2025 security updates)
microsoft Windows 1022H2 (builds prior to the November 2025 security updates)
microsoft Windows 1123H2 (builds prior to the November 2025 security updates)
microsoft Windows 1124H2 (builds prior to the November 2025 security updates)
microsoft Windows 1125H2 (builds prior to the November 2025 security updates)
microsoft Windows Server 2019all builds prior to the November 2025 security updates
microsoft Windows Server 2022all builds prior to the November 2025 security updates
microsoft Windows Server 2022 23H2all builds prior to the November 2025 security updates
microsoft Windows Server 2025all builds prior to the November 2025 security updates
Estimated exposure
masshundreds of millions of Windows endpoints and servers (essentially every supported Windows 10/11 desktop and Windows Server 2019+ host worldwide) — Windows holds roughly 70% desktop OS share across an installed base on the order of 1.4+ billion devices, and Windows Server 2019 through 2025 are ubiquitous in enterprise data centers, so the affected product list spans effectively the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-362, CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news