CVE-2025-60721
Privilege context switching error in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:T/RC:C
- EPSS probability
- 0.36%
- CWE
- CWE-270
- Published
- 2025-11-11
- Last modified
- 2026-03-12
Affected products
- Microsoft Windows 11 Version 24H2
- Microsoft Windows 11 Version 25H2
Weakness type
Related vulnerabilities
- CVE-2026-9560 — Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows...
- CVE-2026-34853 — Permission bypass vulnerability in the LBS module....
- CVE-2025-55210 — FreePBX API has a Privilege Escalation Error in GraphQL Allowing Authenticated Users to Access Additional Scopes
- CVE-2025-9408 — Userspace privilege escalation vulnerability on Cortex M
- CVE-2025-26499 — Under heavy system utilization a random race condition can occur during authentication or token...
- CVE-2025-46406 — A Privilege Context Switching Error (CWE-270) in the Command Center Server could allow a privileged...
- CVE-2025-49583 — XWiki provides no warning when granting XWiki.Notifications.Code.NotificationEmailRendererClass admin right
- CVE-2025-49581 — XWiki allows remote code execution through default value of wiki macro wiki-type parameters