CVE-2025-20660: Medium severity Microsoft PlayReady vulnerability
Published Apr 7, 2025
·Updated
In PlayReady TA, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: DTV04436357; Issue ID: MSV-3186.
Affected Software
4 affected components
Microsoft PlayReady
All of the following
Any of the following
Google Android=12.0
Google Android=14.0
MediaTek Mt9972
Event History
Apr 7, 2025
CVE Published
via MITRE·03:14 AM
Data Sourced
via MITRE·03:14 AM
DescriptionWeakness
Data Sourced
via NVD·04:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-20660?
CVE-2025-20660 has a high severity due to its potential for local privilege escalation.
2
How do I fix CVE-2025-20660?
To fix CVE-2025-20660, apply the recommended patch DTV04436357 as soon as possible.
3
What are the possible impacts of CVE-2025-20660?
CVE-2025-20660 can lead to local escalation of privilege if exploited by a malicious actor with system privileges.
4
Is user interaction required for CVE-2025-20660 exploitation?
No, user interaction is not needed for the exploitation of CVE-2025-20660.
5
Which software is affected by CVE-2025-20660?
CVE-2025-20660 affects Microsoft PlayReady due to a vulnerability in the Trusted Application.