Elevation of Privilege Vulnerability in Windows Media by Microsoft
CVE-2025-49682

7.3HIGH

What is CVE-2025-49682?

A vulnerability in Windows Media could allow an authorized attacker to exploit a use-after-free condition, leading to potential elevation of privileges. If successfully exploited, this flaw would enable the attacker to execute arbitrary code with elevated permissions on the affected system, resulting in unauthorized access and control over sensitive resources.

Affected Version(s)

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6093

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.6093

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.5624

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49682 : Elevation of Privilege Vulnerability in Windows Media by Microsoft