CVE-2025-20661
CVSS 3.1 Score 6.7 of 10 (medium)
Details
Published Apr 7, 2025
Updated: Apr 14, 2025
CWE ID 125
Summary
CVE-2025-20661 is a vulnerability affecting PlayReady TA that involves a missing bounds check, resulting in a possible out-of-bounds read. This issue could potentially allow for local privilege escalation if a system-level attacker has already gained access. Notably, user interaction is not required for exploitation. Microsoft has released a patch with ID DTV04436357 and Issue ID MSV-3185 to address this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Android