CVE-2025-25008

Improper link resolution before file access ('link following') in Microsoft Windows allows an authorized attacker to elevate privileges locally.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.1 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
microsoftCNA
7.1 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H/E:U/RL:O/RC:C
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
microsoftwindows_server_2016
𝑥
< 10.0.14393.7876
microsoftwindows_server_2019
𝑥
< 10.0.17763.7009
microsoftwindows_server_2022
𝑥
< 10.0.20348.3328
microsoftwindows_server_2022_23h2
𝑥
< 10.0.25398.1486
microsoftwindows_server_2025
𝑥
< 10.0.26100.3476
𝑥
= Vulnerable software versions