Elevation of Privilege Vulnerability in Capability Access Management Service by Microsoft
CVE-2025-54108

7HIGH

What is CVE-2025-54108?

A race condition has been identified in the Capability Access Management Service (camsvc), potentially allowing an authorized attacker to manipulate shared resources and elevate privileges within a local environment. This vulnerability compromises the system's integrity by improperly synchronizing access, thereby creating opportunities for unauthorized privilege escalation and enhancing the impact of attacks.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.6584

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.6584

Windows Server 2025 x64-based Systems 10.0.26100.0 < 10.0.26100.6584

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-54108 : Elevation of Privilege Vulnerability in Capability Access Management Service by Microsoft