CVE-2025-60718

Published Nov 11, 2025

Last updated 18 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-60718 is an untrusted search path vulnerability found in Windows Administrator Protection. It enables an authorized attacker to elevate their privileges locally on a vulnerable system. Successful exploitation of CVE-2025-60718 allows an attacker to gain elevated privileges, potentially enabling them to execute commands with higher system access levels. Microsoft released security patches as part of the November 2025 Patch Tuesday updates to address this vulnerability.

Description
Untrusted search path in Windows Administrator Protection allows an authorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed
Products
windows_11_24h2, windows_11_25h2

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-426

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.