Microsoft Windows Broadcast DVR User Service Privilege Escalation Vulnerability
Vulnerability
A use-after-free vulnerability has been identified in the Windows Broadcast DVR User Service, allowing an authorized attacker to locally elevate privileges. This vulnerability requires exploitation of a race condition.
Impact
Successful exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain limited SYSTEM privileges.
Remediation
Users can apply the security update for this vulnerability, which is available through the Microsoft Update Catalog. Specific update details can be found in the Microsoft Knowledge Base articles KB5068781 for various Windows 10 versions, KB5068791 for Windows Server 2019, and KB5068861 for Windows Server 2025. For Windows 11, the update is included in KB5068861 and KB5068966, with additional Hotpatch Update options available.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
