CVE-2025-62215PoC(microsoft / windows_10_1809)

CRITICALCVSS 7.0 · HIGHCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch microsoft windows_10_1809 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.

8.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2025-12-03. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-362CWE-415

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1809
  • windows_10_21h2
  • windows_10_22h2
  • windows_11_23h2

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-02-15); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
windows_10_1809windows_10_21h2windows_10_22h2windows_11_23h2windows_11_24h2windows_11_25h2windows_server_2019windows_server_2022windows_server_2022_23h2windows_server_2025

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-15: 1Mentions · 2026-06-16: 1PoC Mentioned / Linked · 2026-06-16: 1Exploit Tool / Code · 2026-06-16: 1Active Exploitation · 2026-06-16: 1Patch / Workaround · 2026-06-16: 1Technical Details · 2026-02-15: 1Technical Details · 2026-06-16: 102-1506-16
Signal classification2 categories
PoC
150.0%
Active Exploitation
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-151
PoC1
2026-06-161
Active Exploitation1
Full discourse2 posts
  • OS Dev@OSdev_
    Active Exploitation

    One of the latest and most notable Windows privilege escalation vulnerabilities is CVE-2025-62215 in the Windows Kernel - https://github.com/abrewer251/CVE-2025-62215_Windows_Kernel_PE The flaw is a race condition caused by improper synchronization when multiple threads concurrently access shared kernel resources. By carefully winning this race, a local authenticated attacker can manipulate kernel state during execution and cause the operating system to perform privileged operations on behalf of the attacker. Successful exploitation allows escalation from a low-privileged user account to SYSTEM privileges, providing complete control over the affected machine. Because race-condition bugs are often difficult to exploit reliably yet highly impactful when successful, CVE-2025-62215 attracted significant attention after Microsoft confirmed it was being actively exploited in the wild. The vulnerability was addressed in Microsoft's November 2025 security updates by correcting the synchronization logic and preventing unsafe concurrent access to the affected kernel resources.

    Post summary

    CVE‑2025‑62215 is a Windows kernel race‑condition bug enabling local privilege escalation, actively exploited in the wild, with PoC available and patched in Microsoft’s 2025 update.

    011054303.4K
    4.8K followersView on X
  • DbgMan ^_^@0XDbgMan
    PoC

    Dropped 2 Writeups Windows & Driver Internals → Exploitation Kernel Exploit ( CVEs + Root Cause → Exploit) • CVE-2025-62215 • CVE-2024-30088 • CVE-2024-21338 • Stack Overflow & Arbitrary Overwrite (Kernel) https://0xdbgman.github.io/posts/pwning-the-kernel-windows-internals-driver-exploitation/ #ExploitDevelopment

    Post summary

    The tweet announces kernel exploitation writeups covering CVE‑2025‑62215, CVE‑2024‑30088, and CVE‑2024‑21338, with a link that likely contains a Proof of Concept.

    14052615
    350 followersView on X
CPE platform detail11 entries

11 of 11 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_11_24h2---
OSmicrosoftwindows_11_25h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more