Race Condition Vulnerability in Microsoft Windows Secure Channel
CVE-2025-27492
7HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
A vulnerability has been identified in Windows Secure Channel where improper synchronization during concurrent execution with shared resources can be exploited. This weakness allows an authorized attacker to potentially escalate privileges locally. This can lead to unauthorized access and manipulation of sensitive data and system functions. It is essential for users to apply relevant patches and mitigations to protect their systems against potential exploitation.
Affected Version(s)
Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.5191
Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22621.5191
Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.5191
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved