CVE-2025-27488: Microsoft Windows Hardware Lab Kit

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Use of hard-coded credentials in Windows Hardware Lab Kit allows an authorized attacker to elevate privileges locally.

Affected products

  • Microsoft Windows Hardware Lab Kit: before 10.1.17763.7010 (fixed in 10.1.17763.7010); before 10.1.19041.5609 (fixed in 10.1.19041.5609); before 10.1.20348.3330 (fixed in 10.1.20348.3330); before 10.1.22621.5040 (fixed in 10.1.22621.5040); before 10.1.26100.3478 (fixed in 10.1.26100.3478)

Published 2025-05-13. Last modified 2026-06-17.