CVE-2025-55231
published 2025-08-21CVE-2025-55231: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code…
PriorityP347high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.45%
36.1th percentile
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22676 | 6.3.9600.22676 |
| microsoft | windows_server_2016 | < 10.0.14393.8416 | 10.0.14393.8416 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2019 | < 10.0.17763.7783 | 10.0.17763.7783 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2022 | < 10.0.20348.4161 | 10.0.20348.4161 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2025 | < 10.0.26100.6563 | 10.0.26100.6563 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.4652 | 10.0.26100.4652 |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Storage-based Management Service Remote Code Execution Vulnerability
vendor_msrc·2025-08-12·CVSS 7.5
CVE-2025-55231 [HIGH] CWE-362 Windows Storage-based Management Service Remote Code Execution Vulnerability
Windows Storage-based Management Service Remote Code Execution Vulnerability
Description: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to win a race condition.
FAQ: How could an attacker exploit the vulnerability?
An unauthenticated attacker could exploit the vulnerability by sending a malicious http request to the web server. A user would then have to restart the compromised service on the server to trigger the vulnerability.
Windows Storage: Windows Storage
Microsoft: Micros
GHSA
GHSA-cxxx-4vjm-mg8p: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exec
ghsa_unreviewed·2025-08-21
CVE-2025-55231 [HIGH] CWE-362 GHSA-cxxx-4vjm-mg8p: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to exec
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Storage allows an unauthorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-21
Published