Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Now: CUPS 2.4.15 Fixes Critical Flaw Allowing Denial of Service and Code Execution
OpenPrinting released an emergency security update for the Common UNIX Printing System (CUPS) in late November 2025, closing a vulnerability that could let attackers crash the print spooler or...
CVE-2025-62207: Critical Azure Monitor Agent Privilege Escalation Vulnerability Patched
Microsoft has urgently addressed a critical elevation of privilege vulnerability in Azure Monitor Agent, designated CVE-2025-62207, that could allow attackers to gain elevated system privileges on...
Schneider Electric Patches Privilege Escalation in PowerChute Serial Shutdown v1.4
Schneider Electric has issued an urgent security notification addressing multiple critical vulnerabilities in PowerChute Serial Shutdown software, with the company strongly recommending immediate...
CVE-2025-60703: Critical RDS Privilege Escalation Vulnerability Patched
Microsoft has addressed a critical security vulnerability in Windows Remote Desktop Services that could allow local attackers to escalate privileges to SYSTEM level on affected systems. The flaw,...
CVE-2025-59505 Double-Free Bug in Windows Smart Card Grants SYSTEM Access
Microsoft has issued a critical security advisory for CVE-2025-59505, a newly discovered local privilege escalation vulnerability in the Windows Smart Card subsystem that leverages a double-free...
Patch Windows Speech Runtime EoP flaw granting SYSTEM access
Microsoft has addressed a critical elevation-of-privilege vulnerability in the Windows Speech Runtime component, designated CVE-2025-59507, that could allow attackers to gain higher privileges on...
CVE-2025-60719: Critical Windows AFD WinSock Vulnerability Explained
Microsoft has issued an urgent security update addressing CVE-2025-60719, a high-severity local privilege escalation vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that...
CSC zero-day CVE-2025-60705 gives SYSTEM access on Windows 10, 11, and Server.
Microsoft has disclosed a critical elevation of privilege vulnerability in the Windows Client-Side Caching (CSC) service, designated as CVE-2025-60705, affecting the Offline Files functionality that...
CVE-2025-62215: Critical Windows Kernel Privilege Escalation Vulnerability Patched
Microsoft has released an urgent security update addressing CVE-2025-62215, a critical Windows kernel vulnerability that enables local privilege escalation attacks. This race condition flaw in the...
CVE-2025-62213: Critical Windows afd.sys Vulnerability Requires Immediate Patching
Microsoft has issued a critical security alert for CVE-2025-62213, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that enables local privilege...
SQL Server CVE-2025-59499: How Attackers Can Hijack Your Database (And How to Stop Them)
Unauthorized users could seize complete control of an SQL Server instance thanks to a newly patched injection flaw, Microsoft has confirmed. The vulnerability, tracked as CVE-2025-59499, allows an...
CVE-2025-60718: Critical Windows Admin Protection Vulnerability Explained
Microsoft has disclosed a significant security vulnerability in its Windows Administrator Protection feature that could allow attackers to bypass security controls and gain elevated privileges on...