cbcvebase.
CVE-2025-62215
published 2025-11-11

CVE-2025-62215: Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate…

PriorityP185high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2025-12-03
Exploited in the wild
EPSS
6.07%
92.6th percentile
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1809< 10.0.17763.802710.0.17763.8027
microsoftwindows_10_21h2< 10.0.19044.657510.0.19044.6575
microsoftwindows_10_22h2< 10.0.19045.657510.0.19045.6575
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.802710.0.17763.8027
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.657510.0.19044.6575
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.657510.0.19045.6575
microsoftwindows_11_23h2< 10.0.22631.619910.0.22631.6199
microsoftwindows_11_24h2< 10.0.26100.709210.0.26100.7092
microsoftwindows_11_25h2< 10.0.26200.709210.0.26200.7092
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.619910.0.22631.6199
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.619910.0.22631.6199
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.717110.0.26100.7171
microsoftwindows_11_version_25h2>= 10.0.26200.0 < 10.0.26200.717110.0.26200.7171
microsoftwindows_server_2019< 10.0.17763.802710.0.17763.8027
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.802710.0.17763.8027
microsoftwindows_server_2022< 10.0.20348.434610.0.20348.4346
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.440510.0.20348.4405
microsoftwindows_server_2022_23h2< 10.0.25398.196510.0.25398.1965
microsoftwindows_server_2025< 10.0.26100.709210.0.26100.7092
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.717110.0.26100.7171
msrcwindows_10_version_1809
msrcwindows_10_version_21h2
msrcwindows_10_version_22h2
msrcwindows_11_version_23h2
msrcwindows_11_version_24h2

Detection & IOCsextracted from sources · hover to see the quote

snort
Snort rules 65496-65501, 65507-65510 (Snort 2); Snort 3 rules 301343-301345, 301347, 301348
  • Monitor for unusual memory allocation patterns in kernel space as an indicator of CVE-2025-62215 exploitation attempts.
  • Review Windows event logs for privilege escalation attempts, particularly local escalation to SYSTEM-level access.
  • Implement application whitelisting to prevent exploitation tools associated with CVE-2025-62215 from executing.
  • CVE-2025-62215 is being chained with initial access techniques for full network penetration — correlate local privilege escalation events with prior initial access indicators.
  • CVE-2025-62215 is a favourite post-exploitation tool for ransomware operators — prioritise detection of SYSTEM-level token impersonation following low-privilege process execution.
  • ·Talos Snort rules 65496-65501, 65507-65510 and Snort 3 rules 301343-301345, 301347, 301348 cover multiple November 2025 Patch Tuesday vulnerabilities collectively, not exclusively CVE-2025-62215.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.