You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-49690
About this tag
CVE-2025-49690 is a critical local privilege escalation vulnerability in the Windows Capability Access Management Service (camsvc). The flaw stems from a race condition caused by improper synchronization when multiple processes concurrently access shared resources within camsvc. A local attacker can exploit this to escalate privileges to SYSTEM on unpatched Windows systems. Microsoft has released a security advisory and patch; organizations should prioritize applying the update to affected Windows builds. Discussions on WindowsForum cover the technical details, impact, and patching guidance for this vulnerability.
A newly disclosed race‑condition vulnerability in the Windows Capability Access Management Service (camsvc) can be abused by a local attacker to escalate privileges to SYSTEM on unpatched hosts, and organizations should treat the advisory as a high‑priority patching event for affected Windows...
The Capability Access Management Service (camsvc) in Windows has been identified with a critical elevation of privilege vulnerability, designated as CVE-2025-49690. This flaw arises from a race condition due to improper synchronization when multiple processes concurrently access shared resources...