CVE-2025-54913

7.8

Microsoft · Windows UI XAML

A race condition in the Windows UI XAML Maps MapControlSettings component allows an authorized local attacker to elevate privileges to higher levels.

Executive summary

A race condition vulnerability in the Windows UI XAML component allows a locally authenticated attacker to achieve privilege escalation, posing a significant risk to system integrity.

Vulnerability

This vulnerability is a race condition (CWE-362) and use after free (CWE-416) within the MapControlSettings function. An attacker with existing low-level local access can exploit this flaw to execute code or gain elevated privileges on the host system.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its high impact on system security. Successful exploitation allows a local user to bypass security boundaries, potentially granting them full administrative control over the affected workstation or server. This could lead to unauthorized data access, the installation of malicious software, or complete system compromise, significantly impacting organizational security posture.

Remediation

Immediate Action: Apply the September 2025 security updates provided by Microsoft for the affected Windows versions immediately to patch the vulnerable MapControlSettings component.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected privilege escalation events, particularly involving local user accounts.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced for all local user accounts to minimize the potential impact of local privilege escalation.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for full privilege escalation, organizations should prioritize the deployment of these security updates across all affected Windows endpoints. Failure to remediate this vulnerability leaves systems susceptible to local attacks that could result in total compromise of the affected host.

More Microsoft CVEs

Sources