CVE-2025-47987

7.8

Microsoft · Windows

A heap-based buffer overflow in the Windows Credential Security Support Provider (CredSSP) protocol allows an authenticated local attacker to achieve privilege escalation.

Executive summary

A heap-based buffer overflow vulnerability in the Windows CredSSP protocol allows an authenticated attacker to elevate privileges on the local system, posing a high risk to environment security.

Vulnerability

This vulnerability involves a heap-based buffer overflow and integer overflow within the CredSSP protocol, which requires the attacker to possess local authenticated access to the target system.

Business impact

Successful exploitation allows an attacker to elevate their privileges to a higher level, potentially gaining full control over the affected workstation or server. With a CVSS score of 7.8, this vulnerability represents a significant risk to the confidentiality, integrity, and availability of local system data, necessitating prioritized remediation to prevent lateral movement or administrative account compromise.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the overflow conditions in the CredSSP component.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected service crashes associated with the CredSSP process.

Compensating Controls: Enforce strict access control policies to limit the number of users with local interactive login rights, thereby reducing the pool of potential attackers who could exploit this flaw.

Exploitation status

Public Exploit Available: Yes, an entry exists in ExploitDB.

Analyst recommendation

Given the potential for privilege escalation and the availability of public exploit material, this vulnerability should be treated with high urgency. IT administrators must prioritize the deployment of the vendor-supplied patches to all affected Windows endpoints to eliminate the risk of local administrative takeover.

More Microsoft CVEs

Sources