
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64661 is a race condition vulnerability in Windows Shell that allows an authorized local attacker to elevate privileges on affected systems. Classified under CWE-362 (Concurrent Execution Using Shared Resource with Improper Synchronization), it was disclosed and patched by Microsoft on December 9, 2025, as part of the December 2025 Patch Tuesday release. The vulnerability affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability stems from improper synchronization of shared resources during concurrent execution within Windows Shell (CWE-362), a class of flaw commonly associated with TOCTOU (Time-of-Check Time-of-Use) race conditions (CAPEC-29). An attacker with low-level local privileges can exploit the timing window between a resource check and its use to manipulate shared state and gain elevated permissions. Exploitation requires no user interaction but does involve high attack complexity, as the attacker must reliably win the race condition. No public proof-of-concept code has been identified at this time (Microsoft MSRC).
Successful exploitation allows a low-privileged local attacker to escalate to higher privilege levels on the affected Windows system, with high impact to confidentiality, integrity, and availability. The CVSS scope is marked as "Changed," indicating the vulnerability can affect resources beyond the initially compromised component. An attacker could leverage elevated privileges to access sensitive system resources, modify critical configurations, execute malicious code with administrative rights, or facilitate lateral movement within a network environment (Microsoft MSRC).
Microsoft released patches for CVE-2025-64661 on December 9, 2025, as part of the December 2025 Patch Tuesday update cycle. Organizations should apply the relevant cumulative updates for their Windows versions, with fixed builds including: Windows 10 1607/Server 2016 (10.0.14393.8688), Windows 10 1809/Server 2019 (10.0.17763.8146), Windows 10 21H2 (10.0.19044.6691), Windows 10 22H2 (10.0.19045.6691), Windows 11 23H2 (10.0.22631.6345), Windows 11 24H2/Server 2025 (10.0.26100.7392), Windows 11 25H2 (10.0.26200.7392), Windows Server 2022 (10.0.20348.4467), and Windows Server 2022 23H2 (10.0.25398.2025). As interim measures, organizations should enforce least-privilege principles, restrict local user access, and deploy endpoint detection and response (EDR) solutions to monitor for suspicious privilege escalation activity (Microsoft MSRC).
CVE-2025-64661 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-64661 among the privilege escalation issues patched (BleepingComputer). The Zero Day Initiative and Talos Intelligence also published their standard Patch Tuesday reviews covering this vulnerability (ZDI Blog, Talos Intelligence). Sophos and NSFOCUS flagged it in their high-risk vulnerability notices for December 2025 (Sophos News).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."