Race Condition Vulnerability in Microsoft Brokering File System
CVE-2025-54105

7HIGH

What is CVE-2025-54105?

A race condition vulnerability exists in Microsoft Brokering File System, whereby improper synchronization during concurrent execution can be exploited by an authorized attacker to elevate their privileges locally. This flaw can potentially compromise system integrity and security.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.6584

Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 < 10.0.25398.1849

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.6584

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54105 : Race Condition Vulnerability in Microsoft Brokering File System