CVE-2025-49690
HIGHMicrosoft Windows 10 1809 < 10.0.17763.7558 - Race Condition
Title source: ruleDescription
Concurrent execution using shared resource with improper synchronization ('race condition') in Capability Access Management Service (camsvc) allows an unauthorized attacker to elevate privileges locally.
Scores
CVSS v3
7.4
EPSS
0.0004
EPSS Percentile
11.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-415
CWE-362
Status
published
Affected Products (11)
microsoft/windows_10_1809
< 10.0.17763.7558
microsoft/windows_10_1809
< 10.0.17763.7558
microsoft/windows_10_21h2
< 10.0.19044.6093
microsoft/windows_10_22h2
< 10.0.19045.6093
microsoft/windows_11_22h2
< 10.0.22621.5624
microsoft/windows_11_23h2
< 10.0.22631.5624
microsoft/windows_11_24h2
< 10.0.26100.4652
microsoft/windows_server_2019
< 10.0.17763.7558
microsoft/windows_server_2022
< 10.0.20348.3932
microsoft/windows_server_2022_23h2
< 10.0.25398.1732
microsoft/windows_server_2025
< 10.0.26100.4652
Timeline
Published
Jul 08, 2025
Tracked Since
Feb 18, 2026