CVE-2025-24076 | Microsoft Windows Cross Device Service access control
A vulnerability was found in Microsoft Windows 11 22H2/11 23H2/11 24H2/Server 2022 23H2/Server 2025. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Cross Device Service. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2025-24076. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.