CVE-2025-62215
Exploited in the Wild
✓ Confirmed 0-Day
★ Google Project Zero
Triaged: March 3, 2026
4 articles
EPSS Score
Source: FIRST.org · 2026-05-24
2.37%
probability
This CVE has a 2.37% probability
of being exploited in the next 30 days.
0%
Top 85.2th percentile of all CVEs
100%
CVSS score unavailable
Neither CIRCL nor NVD returned a CVSS score for this CVE.
View on VulnerabilityLookup ↗
Description
Project ZeroRace condition leading to double free in kernel
Attack Intelligence
CWE-118
· Incorrect Access of Indexable Resource ('Range Error')
CWE-119
· Buffer Overflow
CWE-1341
CWE-362
· Race Condition
CWE-415
· Double Free
CWE-573
CWE-664
· Improper Control of a Resource Through its Lifetime
CWE-666
· Operation on Resource in Wrong Phase of Lifetime
CWE-672
· Operation on a Resource after Expiration or Release
CWE-675
CWE-691
· Insufficient Control Flow Management
CWE-710
· Improper Adherence to Coding Standards
CWE-825
· Expired Pointer Dereference
Google Project Zero
Patched
Nov. 11, 2025
Reported by
Microsoft Threat Intelligence Center (MSTIC) & Microsoft Security Response Center (MSRC)
Root Cause Analysis
???
Exploits & PoC
dexterm300/CVE-2025-62215-exploit-poc
CVE-2025-62215 is an Elevation of Privilege (EoP) vulnerability in the Windows Kernel, disclosed in November 2025 and confirmed to be actively exploit
31
abrewer251/CVE-2025-62215_Windows_Kernel_PE
This PoC demonstrates a race condition in the Windows kernel leading to a double-free vulnerability, allowing local privilege escalation to SYSTEM. Th
9
theman001/CVE-2025-62215
CVE-2025-62215: Windows Kernel Race Condition + Double-Free EoP
2
3 repos — triés par ⭐
Rechercher sur GitHub ↗
Microsoft Patch Tuesday, November 2025 Security Update Review
Qualys
Nov 11, 2025
Microsoft Fixes 63 Security Flaws, Including a Windows Kernel Zero-Day Under Active Attack
TheHackerNews
Nov 12, 2025
Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
BleepingComputer
Nov 11, 2025
CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks
TheHackerNews
Nov 13, 2025
Signal Intelligence
Confidence
92%
EPSS
2.37%
Mentions
4
Last Seen
Nov 13, 2025
CNA Information
Analyst Note
This CVE is confirmed as a zero-day under active exploitation, with coverage from reputable cybersecurity news sources (TheHackerNews, BleepingComputer) documenting Microsoft's November 2025 patch deployment. The HIGH CVSS score (7.0) combined with active attack evidence and inclusion in Google Project Zero substantiates the confirmed status, though non-inclusion in CISA KEV slightly tempers absolute certainty.
Threat Actors 12
Hacking Team
apt_group
🇮🇹 IT
HAZY TIGER
apt_group
Information theft and espionage
🇮🇳 IN
ArcaneDoor
apt_group
🇨🇳 CN
APT 22
apt_group
Information theft and espionage
🇨🇳 CN
Rocke
apt_group
🇨🇳 CN
APT 6
apt_group
Information theft and espionage
🇨🇳 CN
Red October
apt_group
🇷🇺 RU
Pat Bear
apt_group
🇸🇾 SY
PassCV
apt_group
Information theft and espionage
🇨🇳 CN
Shadow Network
apt_group
Information theft and espionage
🇨🇳 CN
Mana Team
apt_group
🇨🇳 CN
APT 5
apt_group
Information theft and espionage
🇨🇳 CN
Triage Info
Decided atMar 03, 2026