← Back

CVE-2025-27488

nvd nist
Published: May 13, 2025Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: secure@microsoft.com (Secondary)

Description

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

Affected (5)

1 product
Windows Hardware Lab Kit
Configuration A
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 10.1.17763.7010
Running on/withPlatform Versions
Microsoft
Windows 10 1809
All versions
Microsoft
Windows Server 2019
All versions
Configuration B
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
Before 10.1.19041.5609
Running on/withPlatform Versions
Microsoft
Windows 10 2004
All versions
Microsoft
Windows 10 20h2
All versions
Microsoft
Windows 10 21h1
All versions
Microsoft
Windows 10 21h2
All versions
Microsoft
Windows 10 22h2
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.1.20348.3330
Running on/withPlatform Versions
Microsoft
Windows Server 2022
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before 10.1.22621.5040
Running on/withPlatform Versions
Microsoft
Windows 11 22h2
All versions
Configuration E
1 vulnerable · 2 platform
Vulnerable SoftwareAffected Versions
Before 10.1.26100.3478
Running on/withPlatform Versions
Microsoft
Windows 11 24h2
All versions
Microsoft
Windows Server 2025
All versions

References (1)

Timeline

No history available yet.