CVE-2025-27488 is a local privilege escalation vulnerability affecting Microsoft Windows Hardware Lab Kit, stemming from the use of hard-coded credentials (CWE-798). With a CVSS score of 6.7 (Medium), an attacker with high privileges can exploit this with low attack complexity to achieve high impact on confidentiality, integrity, and availability. While no public exploit code exists (Metasploit, Nuclei, ExploitDB), the vulnerability was mentioned in a BleepingComputer article regarding Microsoft's May 2025 Patch Tuesday, indicating some media and community attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.1.17763.7010CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_hardware_lab_kit:*:*:*:*:*:*:*:* | ||
< 10.1.19041.5609CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_hardware_lab_kit:*:*:*:*:*:*:*:* | ||
< 10.1.20348.3330CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_hardware_lab_kit:*:*:*:*:*:*:*:* | ||
< 10.1.22621.5040CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_hardware_lab_kit:*:*:*:*:*:*:*:* | ||
< 10.1.26100.3478CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_hardware_lab_kit:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.