Race Condition Vulnerability in Windows Hyper-V by Microsoft
CVE-2025-54092

7.8HIGH

What is CVE-2025-54092?

A vulnerability exists in Windows Hyper-V due to improper synchronization during concurrent execution using shared resources. This flaw can be exploited by an authorized attacker to elevate their privileges locally, potentially leading to unauthorized control over system resources. It is essential for users and administrators of Windows Hyper-V to review and apply security updates to mitigate this issue. For detailed guidance, refer to the Microsoft advisory.

Affected Version(s)

Windows 10 Version 1809 x64-based Systems 10.0.17763.0 < 10.0.17763.7792

Windows 10 Version 21H2 x64-based Systems 10.0.19044.0 < 10.0.19044.6332

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.6332

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54092 : Race Condition Vulnerability in Windows Hyper-V by Microsoft