HomeDescription
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Wireless Provisioning System allows an authorized attacker to elevate privileges locally.
PUBLISHED Reserved 2025-10-08 | Published 2025-11-11 | Updated 2026-01-02 | Assigner microsoft
HIGH: 7.0CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Problem types
CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Product status
10.0.17763.0 (custom) before 10.0.17763.8027
affected
10.0.19044.0 (custom) before 10.0.19044.6575
affected
10.0.19045.0 (custom) before 10.0.19045.6575
affected
10.0.26200.0 (custom) before 10.0.26200.7171
affected
10.0.22631.0 (custom) before 10.0.22631.6199
affected
10.0.22631.0 (custom) before 10.0.22631.6199
affected
10.0.26100.0 (custom) before 10.0.26100.7171
affected
10.0.14393.0 (custom) before 10.0.14393.8594
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62218 (Microsoft Wireless Provisioning System Elevation of Privilege Vulnerability) vendor-advisory
cve.org (CVE-2025-62218)
nvd.nist.gov (CVE-2025-62218)
Download JSON