CVE-2025-47985

7.8

Microsoft · Windows

An untrusted pointer dereference vulnerability in Windows Event Tracing allows an authorized local attacker to achieve privilege escalation.

Executive summary

Microsoft Windows contains an untrusted pointer dereference flaw in Windows Event Tracing that permits an authenticated local attacker to gain elevated system privileges.

Vulnerability

This vulnerability is a memory corruption issue resulting from an untrusted pointer dereference within the Windows Event Tracing component. Exploitation requires the attacker to possess local authenticated access to the target system.

Business impact

The ability for a local user to escalate privileges to a higher level, such as SYSTEM, poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and the bypass of security controls designed to isolate user processes. Given the CVSS score of 7.8, this high-severity vulnerability represents a significant threat to internal infrastructure and host integrity.

Remediation

Immediate Action: Apply the relevant security updates provided in the Microsoft Security Update Guide for CVE-2025-47985 to all affected Windows endpoints.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or attempts to interact with the Windows Event Tracing service by non-privileged accounts.

Compensating Controls: Ensure the principle of least privilege is strictly enforced across the environment to limit the number of users who possess the local access required to trigger this vulnerability.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

This vulnerability presents a clear risk to host-level security and must be treated with high priority. Organizations should schedule the deployment of the necessary patches during the next maintenance window to ensure all vulnerable systems are protected against potential local privilege escalation attempts.

More Microsoft CVEs

Sources