CVE-2025-21204: Windows Process Activation Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate privileges locally.
Other sources
Windows Process Activation Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22523Patch KB5055557 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25423Patch KB5055581 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27670Patch KB5055570 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23220Patch KB5055596 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.7969Patch KB5055521 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20978Patch KB5055547 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3775Patch KB5055523 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1551Patch KB5055527 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3453Patch KB5055526 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7136Patch KB5055519
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21204?
CVE-2025-21204 has been rated as a high-severity vulnerability, as it allows local privilege escalation.
How do I fix CVE-2025-21204?
To fix CVE-2025-21204, apply the security updates provided by Microsoft for the affected Windows products.
What products are affected by CVE-2025-21204?
CVE-2025-21204 affects multiple Microsoft products, including various versions of Windows Server and Windows 10.
Can an attacker exploit CVE-2025-21204 remotely?
No, CVE-2025-21204 requires local access for an attacker to exploit the vulnerability.
What type of vulnerability is CVE-2025-21204?
CVE-2025-21204 is categorized as an improper link resolution before file access vulnerability.