Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege Vulnerability
Published May 13, 2025
6.7
MEDIUMCVSS 3.1
EPSS 0.38%
Description
Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<10.1.17763.7010
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.19041.5609
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.19041.5609
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.19041.5609
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.19041.5609
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.22621.5040
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.26100.3478
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.19041.5609
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.17763.7010
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.20348.3330
- Version
-
- Version 1.0.0StatusaffectedConstraints<10.1.26100.3478
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Microsoft | Windows 10 HLK Version 1809 | n/a |
| ||||||
| Microsoft | Windows 10 HLK Version 22H2 | n/a |
| ||||||
| Microsoft | Windows 10 HLK version 20H2 | n/a |
| ||||||
| Microsoft | Windows 10 HLK version 21H1 | n/a |
| ||||||
| Microsoft | Windows 10 HLK version 21H2 | n/a |
| ||||||
| Microsoft | Windows 11 HLK 22H2 | n/a |
| ||||||
| Microsoft | Windows 11 HLK 24H2 | n/a |
| ||||||
| Microsoft | Windows HLK for Windows 10 version 2004 | n/a |
| ||||||
| Microsoft | Windows HLK for Windows Server 2019 | n/a |
| ||||||
| Microsoft | Windows HLK for Windows Server 2022 | n/a |
| ||||||
| Microsoft | Windows HLK for Windows Server 2025 | n/a |
|
Configuration 1
- < 10.1.17763.7010
Running on/with
- n/a
- n/a
Configuration 2
- < 10.1.19041.5609
Running on/with
- n/a
- n/a
- n/a
- n/a
- n/a
Configuration 3
- < 10.1.20348.3330
Running on/with
- n/a
Configuration 4
- < 10.1.22621.5040
Running on/with
- n/a
Configuration 5
- < 10.1.26100.3478
Running on/with
- n/a
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
1 other source (NVD) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
TotalDecision
n/aAssessed May 13, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
2025-2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.38% (0.00383) | 30.01th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.36% (0.00364) | 28.06th | v5 (v2026.06.15) |
| May 14, 2025 | 0.05% (0.00048) | 14.87th | v4 (v2025.03.14) |
References (1)
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27488 vendor-advisorypatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27488 | vendor-advisorypatchVendor Advisory |
Change history (0)
No recorded changes yet.