Privilege Elevation Vulnerability in Windows Subsystem for Linux by Microsoft
CVE-2025-53788

7HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
12 August 2025

What is CVE-2025-53788?

A race condition exists within the Windows Subsystem for Linux that allows an authorized attacker to exploit the time-of-check time-of-use (toctou) vulnerability, leading to potential privilege escalation. This issue could enable local attackers to alter the execution flow of the system, granting them elevated permissions and control over sensitive system resources.

Affected Version(s)

Windows Subsystem for Linux (WSL2) Unknown 5.0.0.0 < 2.5.10

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53788 : Privilege Elevation Vulnerability in Windows Subsystem for Linux by Microsoft