CVE-2025-55696: NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability
NtQueryInformation Token function (ntifs.h) Elevation of Privilege Vulnerability
Other sources
Time-of-check time-of-use (toctou) race condition in NtQueryInformation Token function (ntifs.h) allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-55696?
The severity of CVE-2025-55696 is rated as critical due to its potential to enable an elevation of privilege for attackers.
How do I fix CVE-2025-55696?
To fix CVE-2025-55696, ensure you install the latest security updates from Microsoft for the affected product versions.
Which systems are affected by CVE-2025-55696?
CVE-2025-55696 affects multiple versions of Windows 10, Windows 11, and Windows Server products.
What type of vulnerability is CVE-2025-55696?
CVE-2025-55696 is an elevation of privilege vulnerability caused by a time-of-check time-of-use (TOCTOU) race condition.
Can CVE-2025-55696 be exploited remotely?
CVE-2025-55696 cannot be exploited remotely; it requires local access to the affected system.