CVE-2025-24076 is an elevation of privilege vulnerability in Microsoft Windows Cross Device Service caused by improper access control. The flaw allows a locally authorized attacker to exploit insufficient enforcement of security boundaries within the service and elevate privileges on the affected system. Public reporting identifies the issue as a Windows 11 local privilege escalation case that enabled a regular user to obtain administrative privileges.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit for CVE-2025-24076, a local privilege escalation vulnerability in the Microsoft Windows Cross Device Service. The exploit targets Windows 11 (versions 24H2, 23H2, 22H2), Windows Server 2025, and Windows Server 2022 23H2 (Server Core installation). The vulnerability arises from improper access control, allowing a low-privileged attacker to overwrite the 'CrossDevice.Streaming.Source.dll' in a writable directory. The exploit consists of a Python script ('exploit-CVE-2025-24076.py') that automates the process: it builds a malicious DLL (using embedded C code and MinGW's gcc), backs up the original DLL, prompts the user to open the 'Mobile devices' Settings page (to trigger DLL loading), monitors the DLL file until it is unlocked, and then replaces it with the malicious DLL. Upon successful exploitation, the malicious DLL is loaded with SYSTEM privileges, and as proof, it creates the file 'C:\poc_only_admin_can_write_to_c.txt'. The repository also includes a README with detailed usage instructions and a LICENSE file. The exploit requires local access, low privileges, and user interaction, and is intended for educational and research purposes only.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows 11 privilege escalation vulnerability referenced as prior related research involving a regular user gaining administrative privileges.
A Microsoft Windows Cross Device Service elevation of privilege vulnerability listed in the summary table.
Elevation of privilege vulnerability in Microsoft Windows Cross Device Service.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.