Elevation of Privilege Vulnerability in Microsoft Windows Hardware Lab Kit
CVE-2025-27488

6.7MEDIUM

What is CVE-2025-27488?

The Windows Hardware Lab Kit contains hard-coded credentials that can be exploited by an authorized attacker, allowing them to escalate privileges locally. This flaw poses a serious risk as it could enable unauthorized access to sensitive functionalities and data within the system.

Affected Version(s)

Windows 10 HLK Version 1809 Unknown 1.0.0 < 10.1.17763.7010

Windows 10 HLK version 20H2 Unknown 1.0.0 < 10.1.19041.5609

Windows 10 HLK version 21H1 Unknown 1.0.0 < 10.1.19041.5609

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.