First published: Tue Apr 08 2025(Updated: )
<p>Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over a network.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows Server 2022 | ||
Windows 10 | =1607 | |
Windows 11 | =22H2 | |
Microsoft Windows Server 2016 | ||
Windows 10 | =21H2 | |
Windows 11 | =24H2 | |
Microsoft Windows Server 2019 | ||
Windows 10 | =22H2 | |
Microsoft Windows Server 2019 | ||
Windows 10 | =1809 | |
Microsoft Windows Server | ||
Windows 10 | =22H2 | |
Microsoft Windows Server 2025 | ||
Microsoft Windows Server 2016 | ||
Windows 11 | =22H2 | |
Windows 11 | =23H2 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server | ||
Windows 11 | =24H2 | |
Microsoft Windows Server 2012 R2 | ||
Windows 10 | =21H2 | |
Microsoft Windows Server | ||
Microsoft Windows Server 2022 23H2 | ||
Windows 10 | =1607 | |
Microsoft Windows Server 2008 R2 | ||
Microsoft Windows Server 2012 R2 | ||
Microsoft Windows Server | ||
Microsoft Windows Server | ||
Windows 11 | =23H2 | |
Microsoft Windows Server 2022 | ||
Windows 10 | =22H2 | |
Windows 10 | =21H2 | |
Microsoft Windows Server 2025 | ||
Microsoft Windows Server | ||
Windows 10 | =1809 | |
Windows 10 | ||
Windows 10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-27484 is considered a critical vulnerability due to its ability to allow unauthorized privilege escalation over a network.
To fix CVE-2025-27484, apply the latest security patches provided by Microsoft for your affected Windows version.
CVE-2025-27484 affects several Windows versions, including Windows 10, Windows Server 2016, Windows 11, and Windows Server 2022, among others.
Yes, CVE-2025-27484 can be exploited remotely by an authorized attacker to gain elevated privileges.
It is essential to regularly update your systems and monitor for any signs of unauthorized access to mitigate the risks associated with CVE-2025-27484.