Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-54115

CVE-2025-54115: Windows 10 1809 Privilege Escalation Flaw

CVE-2025-54115 is a race condition privilege escalation vulnerability in Windows 10 1809 Hyper-V that enables authorized attackers to elevate privileges locally. This article covers technical details, affected systems, and mitigation.

Updated:

CVE-2025-54115 Overview

CVE-2025-54115 is a race condition vulnerability in Windows Hyper-V that allows an authorized local attacker to elevate privileges. The flaw stems from concurrent execution using shared resources with improper synchronization [CWE-362]. An attacker with low-privilege local access can exploit the timing window to gain higher privileges on the host system.

The vulnerability affects Windows client and server editions running Hyper-V, including Windows 10, Windows 11, and Windows Server 2019 through 2025. Microsoft rates the issue as HIGH severity with a CVSS 3.1 score of 7.0. No public exploit code is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Critical Impact

Successful exploitation grants an attacker elevated privileges on the Hyper-V host, potentially enabling escape from a virtualized boundary and full compromise of the underlying operating system.

Affected Products

  • Microsoft Windows 10 (versions 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 22H2, 23H2, 24H2)
  • Microsoft Windows Server 2019, 2022, 2022 23H2, and 2025

Discovery Timeline

  • 2025-09-09 - CVE-2025-54115 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-54115

Vulnerability Analysis

CVE-2025-54115 is a race condition [CWE-362] within the Windows Hyper-V hypervisor stack. Hyper-V manages virtualization primitives that are accessed by multiple execution contexts, including guest partitions and host worker threads. When these contexts share resources without proper synchronization, an attacker can interleave operations to reach an inconsistent internal state.

By timing operations precisely, a local attacker with low privileges on the host can force Hyper-V to act on stale or attacker-controlled data. This condition can be leveraged to gain SYSTEM-level privileges on the host. The attack complexity is High because it requires reliable timing to win the race window.

Exploitation results in full loss of confidentiality, integrity, and availability on the affected host. The EPSS score of 0.414% suggests limited near-term probability of exploitation, but the impact justifies prompt remediation on any Hyper-V-enabled system.

Root Cause

The root cause is improper synchronization when concurrent code paths in Hyper-V access a shared resource. The absence of adequate locking or atomic operations creates a Time-of-Check to Time-of-Use (TOCTOU) style window. An attacker who repeatedly triggers the affected code path can eventually observe a race outcome that grants unintended access to privileged data or execution flows.

Attack Vector

The attack vector is Local. An attacker must already possess valid credentials with low privileges on the Hyper-V host. Exploitation does not require user interaction. Because Hyper-V executes at a privilege boundary above the operating system kernel, successful exploitation is particularly attractive for guest-to-host escape scenarios or post-compromise privilege escalation on multi-tenant virtualization hosts.

Microsoft has not published exploitation details. See the Microsoft CVE-2025-54115 Update Guide for vendor-supplied information.

Detection Methods for CVE-2025-54115

Indicators of Compromise

  • Unexpected privilege elevation events for standard user accounts on Hyper-V hosts, particularly transitions to SYSTEM or NT AUTHORITY\SYSTEM.
  • Repeated or high-frequency calls to Hyper-V-related system services (vmms.exe, vmwp.exe) from low-privilege user contexts.
  • Anomalous crashes or restarts of the Virtual Machine Management Service that may indicate failed race condition attempts.

Detection Strategies

  • Monitor Windows Security event logs for unexpected process token elevation on Hyper-V hosts.
  • Baseline normal interaction between user-mode processes and Hyper-V worker processes, then alert on statistical deviations.
  • Leverage the Vicarius Detection Script for CVE-2025-54115 to identify unpatched hosts.

Monitoring Recommendations

  • Continuously track patch state across all Hyper-V hosts and correlate with Microsoft's monthly security update releases.
  • Alert on newly created local administrator accounts or scheduled tasks originating from non-administrative sessions.
  • Enable command-line auditing and PowerShell script block logging to capture attempts to interact with Hyper-V APIs.

How to Mitigate CVE-2025-54115

Immediate Actions Required

  • Apply the Microsoft security update referenced in the Microsoft CVE-2025-54115 Update Guide to every affected Windows and Windows Server host.
  • Inventory all systems where the Hyper-V role or Hyper-V Platform feature is enabled, including developer workstations running Windows 10 or 11.
  • Restrict interactive and remote logon rights on Hyper-V hosts to trusted administrators only.

Patch Information

Microsoft has released security updates addressing CVE-2025-54115 across all affected versions of Windows 10, Windows 11, and Windows Server 2019, 2022, 2022 23H2, and 2025. Consult the Microsoft CVE-2025-54115 Update Guide for KB article numbers and download links matching each operating system build. Automated deployment via Windows Update, WSUS, or Microsoft Configuration Manager is recommended.

Workarounds

  • Where patching is not immediately possible, disable the Hyper-V role on hosts that do not require virtualization.
  • Enforce least privilege on Hyper-V hosts and remove standard users from any group with local logon rights.
  • Apply the Vicarius Mitigation Script for CVE-2025-54115 as a temporary compensating control until vendor patches are deployed.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.