CVE-2025-60721 is a high-severity privilege escalation vulnerability affecting Microsoft Windows 11 versions 24H2 and 25H2. This flaw stems from a privilege context switching error within Windows Administrator Protection, allowing an authenticated local attacker to elevate their privileges. With a CVSS score of 7.8, the vulnerability has low attack complexity and can lead to high impacts on confidentiality, integrity, and availability. While there is no known active exploitation, public exploit code, or KEV listing, the vulnerability has garnered significant community discussion and media coverage, indicating a high level of interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.7092CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* | ||
< 10.0.26200.7092CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.