Windows Core Messaging Elevation of Privileges Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
🎯 Affected products27
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 21H2 for 32-bit Systems
- Windows 10 Version 21H2 for ARM64-based Systems
- Windows 10 Version 21H2 for x64-based Systems
- Windows 10 Version 22H2 for 32-bit Systems
- Windows 10 Version 22H2 for ARM64-based Systems
- Windows 10 Version 22H2 for x64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 11 Version 22H2 for ARM64-based Systems
- Windows 11 Version 22H2 for x64-based Systems
- Windows 11 Version 23H2 for ARM64-based Systems
- Windows 11 Version 23H2 for x64-based Systems
- Windows 11 Version 24H2 for ARM64-based Systems
- Windows 11 Version 24H2 for x64-based Systems
- Windows Server 2016
- Windows Server 2016 (Server Core installation)
- Windows Server 2019
- Windows Server 2019 (Server Core installation)
- Windows Server 2022
- Windows Server 2022 (Server Core installation)
- Windows Server 2022, 23H2 Edition (Server Core installation)
- Windows Server 2025
- Windows Server 2025 (Server Core installation)
✅ Remediation
KB5052000 (Security Update) — fixed build 10.0.17763.6893 KB5051979 (Security Update) — fixed build 10.0.20348.3207 KB5052106 (SecurityHotpatchUpdate) — fixed build 10.0.20348.3148 KB5051974 (Security Update) — fixed build 10.0.19044.5487 KB5051989 (Security Update) — fixed build 10.0.22621.4890 KB5051974 (Security Update) — fixed build 10.0.19045.5487 KB5051987 (Security Update) — fixed build 10.0.26100.3194 KB5052105 (SecurityHotpatchUpdate) — fixed build 10.0.26100.3107 KB5051989 (Security Update) — fixed build 10.0.22631.4890 KB5051980 (Security Update) — fixed build 10.0.25398.1425 KB5052040 (Security Update) — fixed build 10.0.10240.20915 KB5052006 (Security Update) — fixed build 10.0.14393.7785
🔗 References (19)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21358
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052000
- referencehttps://support.microsoft.com/help/5052000
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051979
- referencehttps://support.microsoft.com/help/5051979
- referencehttps://support.microsoft.com/help/5052106
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051974
- referencehttps://support.microsoft.com/help/5051974
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051989
- referencehttps://support.microsoft.com/help/5051989
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051987
- referencehttps://support.microsoft.com/help/5051987
- referencehttps://support.microsoft.com/help/5052105
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5051980
- referencehttps://support.microsoft.com/help/5051980
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052040
- referencehttps://support.microsoft.com/help/5052040
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5052006
- referencehttps://support.microsoft.com/help/5052006