Microsoft Windows and Windows Server Capability Access Management Service Privilege Escalation Vulnerability

Vulnerability

A race condition vulnerability has been identified in the Capability Access Management Service (camsvc) on Microsoft Windows and Windows Server platforms. This vulnerability allows an authorized attacker to locally elevate privileges by exploiting improper synchronization in concurrent execution using shared resources.

Impact

Successful exploitation of this vulnerability could allow an attacker to gain SYSTEM privileges.

Remediation

Users can apply the security update for this vulnerability, available through the Microsoft Update Catalog. For Windows Server 2025 and Windows 11 Version 24H2 (both x64-based and ARM64-based systems), the security update can be downloaded using the KB5065426 or KB5065474 links. Windows Server 2025 (Server Core installation) users can also use the same KB links for the security update.

Added: Sep 9, 2025, 6:32 PM
Updated: Sep 9, 2025, 6:32 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
2.9
remediation
0.0
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.