CVE-2025-47985
7.8Microsoft · Windows
An untrusted pointer dereference vulnerability in Windows Event Tracing allows an authorized local attacker to achieve privilege escalation.
Executive summary
Microsoft Windows contains an untrusted pointer dereference flaw in Windows Event Tracing that permits an authenticated local attacker to gain elevated system privileges.
Vulnerability
This vulnerability is a memory corruption issue resulting from an untrusted pointer dereference within the Windows Event Tracing component. Exploitation requires the attacker to possess local authenticated access to the target system.
Business impact
The ability for a local user to escalate privileges to a higher level, such as SYSTEM, poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and the bypass of security controls designed to isolate user processes. Given the CVSS score of 7.8, this high-severity vulnerability represents a significant threat to internal infrastructure and host integrity.
Remediation
Immediate Action: Apply the relevant security updates provided in the Microsoft Security Update Guide for CVE-2025-47985 to all affected Windows endpoints.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or attempts to interact with the Windows Event Tracing service by non-privileged accounts.
Compensating Controls: Ensure the principle of least privilege is strictly enforced across the environment to limit the number of users who possess the local access required to trigger this vulnerability.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability presents a clear risk to host-level security and must be treated with high priority. Organizations should schedule the deployment of the necessary patches during the next maintenance window to ensure all vulnerable systems are protected against potential local privilege escalation attempts.
More Microsoft CVEs
Sources
- Windows Event Tracing Elevation of Privilege Vulnerability Vendor advisory