CVE-2025-20661

CVSS 3.1 Score 6.7 of 10 (medium)

Details

Published Apr 7, 2025
Updated: Apr 14, 2025
CWE ID 125

Summary

CVE-2025-20661 is a vulnerability affecting PlayReady TA that involves a missing bounds check, resulting in a possible out-of-bounds read. This issue could potentially allow for local privilege escalation if a system-level attacker has already gained access. Notably, user interaction is not required for exploitation. Microsoft has released a patch with ID DTV04436357 and Issue ID MSV-3185 to address this vulnerability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share