CVE-2025-24994Improper Access Control in Microsoft Windows 11 Version 22h2

Severity
7.3HIGHNVD
EPSS
0.3%
top 50.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages13 packages

NVDmicrosoft/windows_11_22h2< 10.0.22621.5039
NVDmicrosoft/windows_11_23h2< 10.0.22631.5039
NVDmicrosoft/windows_11_24h2< 10.0.26100.3403
CVEListV5microsoft/windows_11_version_22h210.0.22621.010.0.22621.5039
CVEListV5microsoft/windows_11_version_22h310.0.22631.010.0.22631.5039

🔴Vulnerability Details

1
GHSA
GHSA-w95m-f858-6462: Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally2025-03-11

📋Vendor Advisories

1
Microsoft
Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability2025-03-11

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws2025-03-11
CVE-2025-24994 — Improper Access Control in Microsoft | cvebase