CVE-2025-60703

Published Nov 11, 2025

Last updated 2 months ago

CVSS high 7.8
Windows RDS

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-60703 is a vulnerability in Windows Remote Desktop Services (RDS). It involves an untrusted pointer dereference, which could allow an authorized attacker to elevate their privileges locally on a system. Successful exploitation of CVE-2025-60703 could allow an attacker with local code execution to escalate their privileges to SYSTEM, potentially enabling them to pivot laterally within a network or bypass endpoint isolation controls. Microsoft has assigned a confidence metric to this vulnerability, reflecting their certainty regarding its existence and the credibility of the technical details.

Description
Untrusted pointer dereference in Windows Remote Desktop allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_10_1607, windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_server_2008, windows_server_2012, windows_server_2016, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-822

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.