CVE-2025-62215: Microsoft Windows Race Condition Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access.
— CISA
Windows Kernel Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1965Patch KB5068779 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7171Fixed in 10.0.26200.7092Patch KB5068966 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7171Fixed in 10.0.26100.7092Patch KB5068966 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6199Patch KB5068865 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6575Patch KB5068781 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6575Patch KB5068781 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8027Patch KB5068791 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4405Fixed in 10.0.20348.4346Patch KB5068840
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62215?
CVE-2025-62215 has a critical severity rating due to its potential to allow privilege escalation.
How do I fix CVE-2025-62215?
To fix CVE-2025-62215, apply the relevant patches provided by Microsoft for your affected Windows version.
Which software versions are affected by CVE-2025-62215?
CVE-2025-62215 affects various versions of Windows including Windows 10, Windows 11, and Windows Server 2022 and 2025.
Can CVE-2025-62215 be exploited remotely?
CVE-2025-62215 requires local access to the system for exploitation, thus it cannot be exploited remotely.
What impact does CVE-2025-62215 have on affected systems?
CVE-2025-62215 can allow an attacker to elevate their privileges on the affected Windows system.