CVE-2025-20660

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 18, 2025
CWE ID 125

Summary

CVE-2025-20660 is a vulnerability affecting PlayReady TA that involves a missing bounds check, potentially leading to an out-of-bounds read. This issue could enable local privilege escalation if a malicious actor has already obtained System-level access. No user interaction is required for an attacker to exploit this vulnerability. Microsoft has released a patch with ID DTV04436357 to address this issue, which is identified as MSV-3186.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share