CVE-2025-24994

Published Mar 11, 2025

Last updated 2 months ago

CVSS high 7.3
Windows Cross Device Service

Overview

AI description

Generated using AI and has not been reviewed by Intruder. May contain errors.

CVE-2025-24994 is a vulnerability found in the Windows Cross Device Service. It stems from improper access control, which could allow an attacker with authorization to elevate their privileges on a local system. The vulnerability was published on March 11, 2025. Microsoft is listed as the assigning CNA (CVE Numbering Authority).

Description
Improper access control in Windows Cross Device Service allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Received

Risk scores

CVSS 3.1

Type
Primary
Base score
7.3
Impact score
5.9
Exploitability score
1.3
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-284

Social media

Hype score
Not currently trending