CVE-2025-62215
KEVmass1Local Privilege Escalation via Race Condition in Microsoft Windows Kernel
CISA: Microsoft Windows Race Condition Vulnerability
A race condition (improper synchronization of concurrent access to shared resources, tracked alongside a double-free issue, CWE-362/CWE-415) in the Microsoft Windows Kernel allows an authenticated local attacker to elevate privileges. To trigger it, an attacker with low privileges must run code that races kernel operations on a shared resource; the high attack complexity means timing must line up, but successful races corrupt kernel state and yield elevated execution. A successful exploit grants the attacker kernel/SYSTEM-level access with high impact on confidentiality, integrity, and availability of the host. All Windows 10 builds from 1809 through 22H2, Windows 11 23H2 through 25H2, and Windows Server 2019 through 2025 are affected. Microsoft patched the flaw in its November 2025 Patch Tuesday release, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-11-12 as actively exploited in the wild; no public PoC is known and ransomware use is unconfirmed.
What to do: Apply Microsoft's November 2025 Patch Tuesday security updates for every affected Windows 10, Windows 11, and Windows Server version, prioritizing servers, domain controllers, and multi-user hosts where local privilege escalation has the greatest downstream impact. Because the flaw requires only low local privileges, treat any unpatched system where untrusted users or malware can execute code (RDS/VDI, kiosks, developer workstations) as at risk, and US federal agencies must remediate per CISA BOD 22-01 timelines. After deployment, verify the OS build reflects the November 2025 update, as active exploitation is confirmed even though no public PoC is available.
| microsoft Windows 10 | 1809 (builds prior to the November 2025 security updates) |
| microsoft Windows 10 | 21H2 (builds prior to the November 2025 security updates) |
| microsoft Windows 10 | 22H2 (builds prior to the November 2025 security updates) |
| microsoft Windows 11 | 23H2 (builds prior to the November 2025 security updates) |
| microsoft Windows 11 | 24H2 (builds prior to the November 2025 security updates) |
| microsoft Windows 11 | 25H2 (builds prior to the November 2025 security updates) |
| microsoft Windows Server 2019 | all builds prior to the November 2025 security updates |
| microsoft Windows Server 2022 | all builds prior to the November 2025 security updates |
| microsoft Windows Server 2022 23H2 | all builds prior to the November 2025 security updates |
| microsoft Windows Server 2025 | all builds prior to the November 2025 security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
- Weakness
- CWE-362, CWE-415
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H