CVE-2025-27475

CVSS v3 Score
7.0
High

Vulnerability Description

Sensitive data storage in improperly locked memory in Windows Update Stack allows an authorized attacker to elevate privileges locally.

CVSS:7.0(High)

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability

CVSS:7.0(High)

Windows BrokerInfrastructure Service Elevation of Privilege Vulnerability

CVSS:7.0(High)

Windows Graphics Component Elevation of Privilege Vulnerability

CVSS:7.0(High)

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability