CVE-2025-48799
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
Vendor
Product
CWE
Yayın Tarihi
2025-07-08 17:15:42
Güncelleme
2025-09-26 17:23:01
Source Identifier
secure@microsoft.com
KEV Date Added
-
Kategoriler
Referanslar
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48799
https://www.vicarius.io/vsociety/posts/cve-2025-48799-detection-script-elevation-of-privilege-vulnerability-in-windows-update-service
https://www.vicarius.io/vsociety/posts/cve-2025-48799-mitigation-script-elevation-of-privilege-vulnerability-in-windows-update-service