CVE-2025-64658: Windows File Explorer Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.
Other sources
Windows File Explorer Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6345Patch KB5071417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4529Fixed in 10.0.20348.4467Patch KB5071413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8146Patch KB5071544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2025Patch KB5071542
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64658?
CVE-2025-64658 is classified as a critical vulnerability with the potential for privilege escalation.
How do I fix CVE-2025-64658?
The recommended fix for CVE-2025-64658 involves applying the latest security updates provided by Microsoft.
What platforms are affected by CVE-2025-64658?
CVE-2025-64658 affects various versions of Microsoft Windows including Windows 10, Windows 11, and Windows Server editions.
Can an attacker exploit CVE-2025-64658 remotely?
CVE-2025-64658 requires local access, making it necessary for an attacker to be physically present to exploit the vulnerability.
Is user interaction required to exploit CVE-2025-64658?
Yes, exploiting CVE-2025-64658 typically requires some level of user interaction.