CVE-2025-49690

HIGH

Windows 10/11, Server 2019/2022/2025 - Unauthenticated Privilege Escalation via Race Condition

Title source: llm
STIX 2.1

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.

References (1)

Core 1
Core References

Scores

CVSS v3 7.4
EPSS 0.0025
EPSS Percentile 15.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-415 CWE-362
Status published
Products (10)
microsoft/windows_10_1809 < 10.0.17763.7558 (2 CPE variants)
microsoft/windows_10_21h2 < 10.0.19044.6093
microsoft/windows_10_22h2 < 10.0.19045.6093
microsoft/windows_11_22h2 < 10.0.22621.5624
microsoft/windows_11_23h2 < 10.0.22631.5624
microsoft/windows_11_24h2 < 10.0.26100.4652
microsoft/windows_server_2019 < 10.0.17763.7558
microsoft/windows_server_2022 < 10.0.20348.3932
microsoft/windows_server_2022_23h2 < 10.0.25398.1732
microsoft/windows_server_2025 < 10.0.26100.4652
Published Jul 08, 2025
Tracked Since Feb 18, 2026