CVE-2025-58727: Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58727?
CVE-2025-58727 is classified as an Elevation of Privilege vulnerability.
How do I fix CVE-2025-58727?
To fix CVE-2025-58727, apply the latest security updates provided by Microsoft for the affected Windows versions.
Which systems are affected by CVE-2025-58727?
CVE-2025-58727 affects Windows 10, Windows 11, and Windows Server editions, specifically versions such as 21H2, 22H2, 23H2, 24H2, and 25H2.
What type of vulnerability is CVE-2025-58727?
CVE-2025-58727 is a race condition vulnerability that allows an authorized attacker to elevate their privileges.
Can CVE-2025-58727 be exploited remotely?
CVE-2025-58727 requires local access to exploit, meaning it cannot be exploited remotely.