
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62570 is an improper access control vulnerability (CWE-284) in the Windows Camera Frame Server Monitor component that allows an authenticated local attacker with low privileges to disclose sensitive information. It affects Windows 11 versions 24H2 and 25H2, as well as Windows Server 2025 (including Server Core installations). Microsoft disclosed and patched the vulnerability on December 9, 2025, as part of the December 2025 Patch Tuesday release. The CVSS v3.1 base score is 5.5 (Medium), though ENISA rates it at 7.1 based on an adjusted vector that also includes high integrity impact (Microsoft MSRC, BleepingComputer).
The root cause is improper access control (CWE-284) within the Windows Camera Frame Server Monitor service, which fails to adequately restrict access to sensitive data for low-privileged local users. The attack vector is local, requiring the attacker to already have an authenticated session on the target system with low-level privileges; no user interaction or elevated complexity is needed. The vulnerability enables unauthorized information disclosure from the Camera Frame Server Monitor component, and the ENISA scoring also attributes a high integrity impact, suggesting potential for data modification in addition to disclosure (Microsoft MSRC, Feedly). No public technical write-ups or proof-of-concept code have been identified.
Successful exploitation allows an authenticated local attacker with low privileges to access sensitive information handled by the Windows Camera Frame Server Monitor, potentially including camera frame data or related system information. The ENISA assessment also indicates a high integrity impact, meaning an attacker may be able to modify system data in addition to reading it. The scope is limited to the local system (no network propagation), but the vulnerability could be leveraged as part of a broader privilege escalation or lateral movement chain on multi-user or shared systems (Microsoft MSRC).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053%, indicating a very low probability of exploitation in the near term. No threat actor attribution has been reported in connection with this CVE.
Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday update. Affected systems should be updated to build 10.0.26100.7392 or later (Windows 11 24H2 / Windows Server 2025) or 10.0.26200.7392 or later (Windows 11 25H2). No configuration-based workarounds have been published; applying the security update is the recommended remediation. Additionally, organizations should enforce the principle of least privilege for local accounts and monitor system logs for unusual access patterns to the Camera Frame Server Monitor service (Microsoft MSRC, BleepingComputer).
CVE-2025-62570 received routine coverage as part of the broader December 2025 Patch Tuesday roundup, which addressed 57 flaws including 3 zero-days. Security outlets such as BleepingComputer, CyberSecurityNews, and GBHackers covered the patch release, but no specific commentary focused on this individual CVE. The Zero Day Initiative's December 2025 update review and Sophos's Patch Tuesday blog also mentioned the release without singling out this vulnerability (BleepingComputer, ZDI, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."