Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Kernel allows an authorized attacker to elevate privileges locally.
Published: 2025-11-11
CVE-2025-62215 Windows Kernel vulnerability exploited in the wild as zero-day, one of 63 CVEs patched in the November 2025 Patch Tuesday release.
https://www.securityweek.com/critical-watchguard-firebox-vulnerability-exploited-in-attacks/
https://www.helpnetsecurity.com/2025/11/13/cisa-directive-cve-2025-20333-cve-2025-20362/
https://thehackernews.com/2025/11/cisa-flags-critical-watchguard-fireware.html
https://www.infosecurity-magazine.com/news/microsoft-windows-kernel-zero-day/
https://www.helpnetsecurity.com/2025/11/12/patch-tuesday-microsoft-cve-2025-62215/
https://thehackernews.com/2025/11/microsoft-fixes-63-security-flaws.html
https://www.securityweek.com/microsoft-patches-actively-exploited-windows-kernel-zero-day/
https://cyberscoop.com/microsoft-patch-tuesday-november-2025/
https://www.tenable.com/blog/microsofts-november-2025-patch-tuesday-addresses-63-cves-cve-2025-62215
https://www.tenable.com/blog/frequently-asked-questions-about-the-august-2025-f5-security-incident
https://github.com/echeys01/cve-json-analysis-5.x
https://github.com/theman001/CVE-2025-62215
https://github.com/32BitZ-Studio/Total-POC-CVE
https://github.com/mrk336/Kernel-Chaos-Weaponizing-CVE-2025-62215-for-SYSTEM-Privilege-Escalation
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-62215