CVE-2025-27731: Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability
Improper input validation in OpenSSH for Windows allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft OpenSSH for Windows Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.3775Patch KB5055523 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1551Patch KB5055527 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.5189Patch KB5055528 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.5737Patch KB5055518 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7136Patch KB5055519 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.3453Patch KB5055526
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27731?
The severity of CVE-2025-27731 is considered high due to its potential for allowing an authorized attacker to elevate privileges locally.
How do I fix CVE-2025-27731?
To fix CVE-2025-27731, apply the appropriate security patches provided by Microsoft for affected versions of Windows and OpenSSH.
Which software versions are affected by CVE-2025-27731?
CVE-2025-27731 affects Microsoft Windows Server 2022, Windows Server 2019, Windows 10, and Windows 11 across multiple versions and editions.
What impact does CVE-2025-27731 have on systems?
CVE-2025-27731 allows an authorized attacker to execute code with elevated privileges, posing significant security risks to system integrity.
Is there a workaround for CVE-2025-27731?
While applying the patch is the recommended solution for CVE-2025-27731, administrators should also review access controls to limit potential exploitation.