Improper access control in Windows and Windows Server - CVE-2025-24076
Published: March 11, 2025 / Updated: June 13, 2025
Windows
Windows Server
Detailed vulnerability description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Windows Cross Device Service. A local user can bypass implemented security restrictions and gain elevated privileges on the target system.