CVE-2025-24076

Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

History

07 Jul 2025, 17:24

Type Values Removed Values Added
Summary
  • (es) Un control de acceso inadecuado en el servicio de dispositivos cruzados de Windows permite que un atacante autorizado eleve privilegios localmente.
First Time Microsoft windows 11 22h2
Microsoft windows 11 24h2
Microsoft
Microsoft windows Server 2022 23h2
Microsoft windows 11 23h2
Microsoft windows Server 2025
CPE cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24076 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24076 - Vendor Advisory

11 Mar 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 17:16

Updated : 2025-07-07 17:24


NVD link : CVE-2025-24076

Mitre link : CVE-2025-24076

CVE.ORG link : CVE-2025-24076


JSON object : View

Products Affected

microsoft

  • windows_11_22h2
  • windows_11_24h2
  • windows_11_23h2
  • windows_server_2022_23h2
  • windows_server_2025
CWE
CWE-284

Improper Access Control