CVE-2025-58727
14.10.2025, 17:15
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Connected Devices Platform Service allows an authorized attacker to elevate privileges locally.| Vendor | Product | Version |
|---|---|---|
| microsoft | windows_10_21h2 | 𝑥 < 10.0.19044.6456 |
| microsoft | windows_10_22h2 | 𝑥 < 10.0.19045.6456 |
| microsoft | windows_11_22h2 | 𝑥 < 10.0.22621.6060 |
| microsoft | windows_11_23h2 | 𝑥 ≤ 10.0.22631.6060 |
| microsoft | windows_11_24h2 | 𝑥 < 10.0.26100.6899 |
| microsoft | windows_11_25h2 | 𝑥 < 10.0.26200.6899 |
| microsoft | windows_server_2022_23h2 | 𝑥 < 10.0.25398.1913 |
| microsoft | windows_server_2025 | 𝑥 ≤ 10.0.26100.6899 |
𝑥
= Vulnerable software versions