HomeDescription
Concurrent execution using shared resource with improper synchronization ('race condition') in Universal Print Management Service allows an authorized attacker to elevate privileges locally.
PUBLISHED Reserved 2025-03-11 | Published 2025-05-13 | Updated 2026-02-26 | Assigner microsoft
HIGH: 7.0CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Problem types
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CWE-416: Use After Free
Product status
10.0.19044.0 (custom) before 10.0.19044.5854
affected
10.0.19045.0 (custom) before 10.0.19045.5854
affected
10.0.22621.0 (custom) before 10.0.22621.5335
affected
10.0.22631.0 (custom) before 10.0.22631.5335
affected
10.0.22631.0 (custom) before 10.0.22631.5335
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
10.0.20348.0 (custom) before 10.0.20348.3692
affected
10.0.25398.0 (custom) before 10.0.25398.1611
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
10.0.26100.0 (custom) before 10.0.26100.4061
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29841 (Universal Print Management Service Elevation of Privilege Vulnerability) vendor-advisory patch
cve.org (CVE-2025-29841)
nvd.nist.gov (CVE-2025-29841)
Download JSON