Improper access control in Microsoft Windows and Windows Server - CVE-2025-24076
Published: March 11, 2025 / Updated: June 13, 2025
Vulnerability details
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions in Microsoft Windows Cross Device Service. A local user can bypass implemented security restrictions and gain elevated privileges on the target system.
Affected software
Windows Server
How to mitigate CVE-2025-24076
Windows Server - addressed in versions 2012 R2 6.3.9600.22470, 2022 23H2 10.0.25398.1486, 2025 10.0.26100.3403, 2025 10.0.26100.3476