Cyber Security News

Windows Kernel 0‑day Vulnerability Actively Exploited in the Wild to Escalate Privilege

Microsoft has assigned CVE-2025-62215 to a new Windows Kernel elevation of privilege flaw that is being actively exploited in the wild.

Published on November 11, 2025, the vulnerability is rated Important and tracked as an elevation of privilege issue in the kernel. Microsoft’s exploitability index lists “Exploitation Detected,” indicating real-world use despite the absence of public disclosure.

CVE-2025-62215 stems from concurrent execution using a shared resource with improper synchronization, aligning with CWE-362 (race condition), and is also associated with CWE-415 (double free).

Successful exploitation requires an attacker to win a race condition (CVSS Attack Complexity: High), but when it lands, it can grant SYSTEM privileges.

The flaw is local and requires an already authorized attacker, making it a classic post-compromise privilege escalation used to deepen control, disable defenses, and move laterally.

While technical specifics remain limited, the combination of race condition and double free suggests a timing-sensitive memory corruption path in kernel code.

This profile is consistent with techniques favored by both targeted threat actors and ransomware operators to elevate privileges after initial access via phishing, driver abuse, or application exploits.

Windows VersionAffectedFixed KB NumberRelease DateNotes
Windows 10 (various builds, including ESU)YesKB5068858 (example for 22H2)November 12, 2025All supported editions affected; ESU required for post-support patching.
Windows 11 version 22H2YesKB5068865November 12, 2025Core kernel component; immediate patching recommended.
Windows 11 version 23H2YesKB5068862November 12, 2025Includes security and quality fixes addressing the race condition.
Windows 11 version 24H2YesKB5068861November 12, 2025Latest feature update; exploitation detected pre-patch.
Windows Server 2019YesKB5068859November 12, 2025Server environments at higher risk due to privilege escalation potential.
Windows Server 2022YesKB5068860November 12, 2025Applies to domain controllers and file servers; monitor for updates.
Windows Server 2025YesKB5068861November 12, 2025New server OS; aligns with Windows 11 24H2 patching.

Given that exploitation has been detected but no public proof-of-concept is available, expect continued targeted use.

Organizations should treat CVE-2025-62215 as a priority for rapid patching and detection engineering, with special attention to servers, jump hosts, and administrative workstations.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

4 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

6 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago