CVE-2025-60707

7.8

Microsoft · Windows

A use after free vulnerability in the Multimedia Class Scheduler Service (MMCSS) allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A high-severity use after free flaw in the Windows Multimedia Class Scheduler Service allows an authenticated attacker to elevate privileges on the local system.

Vulnerability

This is a use after free vulnerability (CWE-416) within the Multimedia Class Scheduler Service (MMCSS). The flaw permits an attacker who already possesses low-level local user privileges to execute code with elevated rights, effectively bypassing standard security restrictions.

Business impact

Successful exploitation of this vulnerability allows a local user to gain unauthorized administrative or system-level access to the host. Given the CVSS score of 7.8, this represents a significant security risk, as it enables lateral movement, data exfiltration, or the installation of persistent malware, potentially compromising the integrity of the entire workstation or server.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the November 2025 update cycle to all affected Windows systems.

Proactive Monitoring: Monitor local system logs for unusual process execution patterns or unexpected service interactions involving the Multimedia Class Scheduler Service.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced, limiting the number of users who possess local interactive login rights on sensitive systems.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the official Microsoft security patches to all impacted Windows environments. Because this vulnerability facilitates privilege escalation, it is an essential component of maintaining a secure defense-in-depth architecture, and patching should be conducted according to standard vulnerability management timelines.

More Microsoft CVEs

Sources