Microsoft Windows Core Messaging Elevation of Privileges Vulnerability

Vulnerability

A vulnerability allowing elevation of privileges has been identified in the Windows Core Messaging component. This issue could enable an attacker to gain SYSTEM privileges. The vulnerability affects multiple Windows versions, including Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, Windows Server 2022, and Windows Server 2025. The root cause is an untrusted pointer dereference, which could be exploited under certain conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized elevation of privileges, allowing an attacker to gain SYSTEM rights.

Remediation

Users can apply the security updates provided by Microsoft to address this vulnerability. These security updates are available through the Microsoft Update Catalog.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.