CVE-2025-64661

7.8

Microsoft · Windows

A race condition vulnerability in the Windows Shell allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A critical race condition vulnerability in the Microsoft Windows Shell allows an authenticated attacker to elevate privileges on the local system.

Vulnerability

This vulnerability involves a race condition, identified as CWE-362, occurring within the Windows Shell. It allows an authorized, locally authenticated attacker to manipulate shared resources and elevate their privileges.

Business impact

The ability for a local attacker to escalate privileges represents a significant security risk, as it allows unauthorized access to administrative functions and sensitive data. With a CVSS score of 7.8, this flaw is categorized as High severity: it provides a pathway for lateral movement or full system compromise once an initial low-privileged foothold is established.

Remediation

Immediate Action: Administrators must apply the latest security updates provided by Microsoft for the affected Windows versions to address the race condition.

Proactive Monitoring: Security teams should monitor system logs for unusual process execution patterns or unexpected administrative actions performed by low-privileged user accounts.

Compensating Controls: Ensure that Endpoint Detection and Response (EDR) solutions are active to detect and block abnormal behavior associated with shell-based privilege escalation attempts.

Exploitation status

Public Exploit Available: No.

Analyst recommendation

Given the potential for privilege escalation and the high severity score, organizations should prioritize the deployment of the relevant Microsoft security patches. While this vulnerability requires local access, it is a critical component of post-exploitation activity and must be remediated to maintain a robust security posture and prevent unauthorized administrative access.

More Microsoft CVEs

Sources