CVE-2025-24076
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 284
Summary
CVE-2025-24076 is a newly identified vulnerability in Windows Cross Device Service. This issue involves a lack of adequate access controls, enabling an attacker who has already gained authorized access to the system to further elevate their privileges within the local environment. This vulnerability poses a significant risk for malicious actors looking to escalate their attack once they have initially gained a foothold in the system. Windows users are strongly urged to apply the available patches to mitigate this vulnerability as soon as possible.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 11
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft