← Back to browse · API

CVE-2025-54918

Severity
HIGH
CVSS
8.8
EPSS
0.19354
Risk score
41.97
CISA KEV
No
PoC
No
Published
2025-09-09
Modified
2026-02-20
First seen
2026-08-07
Aliases
EUVD-2025-27346, GHSA-75V4-RJ2V-3F53
Products
Microsoft:Windows 10 Version 1507 10.0.10240.0 <10.0.10240.21128, Microsoft:Windows 10 Version 1607 10.0.14393.0 <10.0.14393.8422, Microsoft:Windows 10 Version 1809 10.0.17763.0 <10.0.17763.7792, Microsoft:Windows 10 Version 21H2 10.0.19044.0 <10.0.19044.6332, Microsoft:Windows 10 Version 22H2 10.0.19045.0 <10.0.19045.6332, Microsoft:Windows 11 Version 23H2 10.0.22631.0 <10.0.22631.5909, Microsoft:Windows 11 Version 24H2 10.0.26100.0 <10.0.26100.6584, Microsoft:Windows 11 version 22H2 10.0.22621.0 <10.0.22621.5909, Microsoft:Windows 11 version 22H3 10.0.22631.0 <10.0.22631.5909, Microsoft:Windows Server 2008 R2 Service Pack 1 (Server Core installation) 6.1.7601.0 <6.1.7601.27929, Microsoft:Windows Server 2008 R2 Service Pack 1 6.1.7601.0 <6.1.7601.27929, Microsoft:Windows Server 2008 Service Pack 2 (Server Core installation) 6.0.6003.0 <6.0.6003.23529, Microsoft:Windows Server 2008 Service Pack 2 6.0.6003.0 <6.0.6003.23529, Microsoft:Windows Server 2012 (Server Core installation) 6.2.9200.0 <6.2.9200.25675, Microsoft:Windows Server 2012 6.2.9200.0 <6.2.9200.25675, Microsoft:Windows Server 2012 R2 (Server Core installation) 6.3.9600.0 <6.3.9600.22774, Microsoft:Windows Server 2012 R2 6.3.9600.0 <6.3.9600.22774, Microsoft:Windows Server 2016 (Server Core installation) 10.0.14393.0 <10.0.14393.8422, Microsoft:Windows Server 2016 10.0.14393.0 <10.0.14393.8422, Microsoft:Windows Server 2019 (Server Core installation) 10.0.17763.0 <10.0.17763.7792, Microsoft:Windows Server 2019 10.0.17763.0 <10.0.17763.7792, Microsoft:Windows Server 2022 10.0.20348.0 <10.0.20348.4171, Microsoft:Windows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 <10.0.25398.1849, Microsoft:Windows Server 2025 (Server Core installation) 10.0.26100.0 <10.0.26100.6584, Microsoft:Windows Server 2025 10.0.26100.0 <10.0.26100.6584
Sources
euvd EUVD-2025-27346

Description

Improper authentication in Windows NTLM allows an authorized attacker to elevate privileges over a network.

References