Elevation of Privileges Vulnerability in OpenSSH for Windows
CVE-2025-27731
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
An improper input validation vulnerability in OpenSSH for Windows allows an authorized attacker to escalate privileges locally. This exploitation can lead to unauthorized access and manipulation of sensitive systems. Organizations utilizing OpenSSH for Windows should review their security measures and apply necessary patches to safeguard against this type of attack.
Affected Version(s)
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7137
Windows 10 Version 21H2 32-bit Systems 10.0.19043.0 < 10.0.19044.5737
Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.5737
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved