Home
HIGH: 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.22621.0 (custom) before 10.0.22621.5039
affected
10.0.22631.0 (custom) before 10.0.22631.5039
affected
10.0.22631.0 (custom) before 10.0.22631.5039
affected
10.0.26100.0 (custom) before 10.0.26100.3476
affected
Description
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Problem types
CWE-284: Improper Access Control
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24994 (Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability)