« Back to list

CVE-2025-48799

Status: AnalyzedHigh (7.8)—

Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

CWE-59 (link following) con AV:L/PR:L/UI:N permite escalada de privilegios local sin interacción. Windows Update Service vulnerable a symlink attacks para elevar a SYSTEM.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (8)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-48799",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-48799",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-07-08T19:19:46.769327Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1607",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.14393.0",
              "lessThan": "10.0.14393.8246",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 1809",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.17763.0",
              "lessThan": "10.0.17763.7558",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 21H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19044.0",
              "lessThan": "10.0.19044.6093",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 10 Version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.19045.0",
              "lessThan": "10.0.19045.6093",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "32-bit Systems",
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 22H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22621.0",
              "lessThan": "10.0.22621.5624",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 version 22H3",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22631.0",
              "lessThan": "10.0.22631.5624",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 Version 23H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.22631.0",
              "lessThan": "10.0.22631.5624",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows 11 Version 24H2",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4652",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "ARM64-based Systems",
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2025",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4652",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Server 2025 (Server Core installation)",
          "versions": [
            {
              "status": "affected",
              "version": "10.0.26100.0",
              "lessThan": "10.0.26100.4652",
              "versionType": "custom"
            }
          ],
          "platforms": [
            "x64-based Systems"
          ]
        }
      ]
    }
  ],
  "published": "2025-07-08T17:15:42.720",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48799",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    },
    {
      "url": "https://www.vicarius.io/vsociety/posts/cve-2025-48799-detection-script-elevation-of-privilege-vulnerability-in-windows-update-service",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.vicarius.io/vsociety/posts/cve-2025-48799-mitigation-script-elevation-of-privilege-vulnerability-in-windows-update-service",
      "tags": [
        "Exploit",
        "Mitigation",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-59"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally."
    },
    {
      "lang": "es",
      "value": "La resolución incorrecta de un vínculo antes del acceso a un archivo ('seguimiento de un vínculo') en Windows Update Service permite que un atacante autorizado eleve privilegios localmente."
    }
  ],
  "lastModified": "2026-06-17T09:30:19.030",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "3CEAC32A-5246-4F6B-8DD5-E49F3BA621DA",
              "versionEndExcluding": "10.0.14393.8246"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "E0A0243D-52B4-49AE-B1AE-263640C492B0",
              "versionEndExcluding": "10.0.14393.8246"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
              "vulnerable": true,
              "matchCriteriaId": "2062C268-282B-4E52-9F8C-876A2D483EAD",
              "versionEndExcluding": "10.0.17763.7558"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
              "vulnerable": true,
              "matchCriteriaId": "00FCA704-C6E0-4DE4-86F0-80552527AE53",
              "versionEndExcluding": "10.0.17763.7558"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50848190-CF61-47F6-90B8-DB0C120749F5",
              "versionEndExcluding": "10.0.19044.6093"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "01E62E99-5EDA-487C-A941-E2DA348B501F",
              "versionEndExcluding": "10.0.19045.6093"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "76FEE1E8-EB22-4E01-86D7-13B35F9D2876",
              "versionEndExcluding": "10.0.22621.5624"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19D0DAB7-4BFF-4BB7-9E0E-B020CF8573C9",
              "versionEndExcluding": "10.0.22631.5624"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E866DB2-9CA7-4BCC-8591-9BC94300B779",
              "versionEndExcluding": "10.0.26100.4652"
            },
            {
              "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10E640FB-32AB-45B6-BC42-56CC587C0A35",
              "versionEndExcluding": "10.0.26100.4652"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}