CVE-2025-27468Improper Privilege Management in Microsoft Windows 10 Version 1507

Severity
7.0HIGHNVD
EPSS
0.2%
top 53.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages24 packages

NVDmicrosoft/windows< 10.0.14393.8066+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21014
NVDmicrosoft/windows_10_1607< 10.0.14393.8066
NVDmicrosoft/windows_10_1809< 10.0.17763.7314
NVDmicrosoft/windows_10_21h2< 10.0.19044.5854

🔴Vulnerability Details

2
CVEList
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability2025-05-13
GHSA
GHSA-fxh5-h665-pxfj: Improper privilege management in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Kernel-Mode Driver Elevation of Privilege Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-27468 — Improper Privilege Management | cvebase