CVE-2025-24994

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*

History

03 Jul 2025, 17:22

Type Values Removed Values Added
Summary
  • (es) Un control de acceso inadecuado en el servicio de dispositivos cruzados de Windows permite que un atacante autorizado eleve privilegios localmente.
First Time Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows 11 22h2
CPE cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24994 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24994 - Vendor Advisory

11 Mar 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 17:16

Updated : 2025-07-03 17:22


NVD link : CVE-2025-24994

Mitre link : CVE-2025-24994

CVE.ORG link : CVE-2025-24994


JSON object : View

Products Affected

microsoft

  • windows_11_23h2
  • windows_11_24h2
  • windows_11_22h2
CWE
CWE-284

Improper Access Control