Microsoft Windows Server 2025
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*
A vulnerability allowing elevation of privilege has been identified in Windows Secure Kernel mode. This issue affects several different versions and ranges of Windows 10, Windows 11, Windows Server 2025, and Windows Server 2025 (Server Core installation). The vulnerability arises from incorrect permission assignments for critical resources, enabling authenticated attackers to escalate privileges by overwriting page table data intended for the kernel. This vulnerability impacts ARM64 architecture only.
Exploitation of this vulnerability allows authenticated attackers to escalate privileges to Secure Kernel mode.
Microsoft recommends that customers install the security update KB5050009 for Windows Server 2025, KB5049981 for Windows 10 Version 22H2 and 21H2, and KB5050021 for Windows 11 Versions 22H2 and 24H2. For Windows 11 Version 23H2, the security update KB5050021 should be installed. Customers can download these updates through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.