CVE-2025-47973

7.8

Microsoft · Windows

A buffer over-read vulnerability in the Virtual Hard Disk (VHDX) implementation allows an unauthorized local attacker to achieve privilege escalation.

Executive summary

A buffer over-read vulnerability in the Windows Virtual Hard Disk (VHDX) driver allows local attackers to elevate privileges, posing a significant risk to system integrity.

Vulnerability

This is a buffer over-read flaw (CWE-126) within the VHDX processing component. The vulnerability can be triggered locally by an unauthorized attacker, requiring user interaction to execute.

Business impact

Successful exploitation of this vulnerability allows an attacker to elevate their privileges on an affected system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, and the potential for lateral movement within the network.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to patch the vulnerable VHDX driver.

Proactive Monitoring: Monitor system logs for unusual crashes or error events associated with disk management services or VHDX mounting operations.

Compensating Controls: Implement strict endpoint controls to restrict the ability of unauthorized users to mount or interact with virtual disk files.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations should prioritize the deployment of the security updates referenced in the Microsoft security update guide. Although local access is required, the potential for privilege escalation makes this a critical maintenance item for all affected Windows environments to prevent unauthorized administrative control.

More Microsoft CVEs

Sources