CVE-2025-55233

7.8

Microsoft · Windows

A local out-of-bounds read vulnerability in the Windows Projected File System allows an authenticated attacker to achieve local privilege escalation.

Executive summary

An out-of-bounds read vulnerability in the Windows Projected File System allows a local authenticated attacker to escalate privileges, posing a significant risk to system integrity.

Vulnerability

The flaw is an out-of-bounds read (CWE-125) within the Windows Projected File System. It requires the attacker to have local access and low-level privileges to trigger the condition, potentially leading to unauthorized system actions.

Business impact

Successful exploitation of this vulnerability allows a local attacker to elevate their privileges to a higher level, potentially gaining control over the affected system. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as it facilitates unauthorized access and potential compromise of sensitive data or system stability.

Remediation

Immediate Action: Apply the specific security updates provided by Microsoft for the affected Windows versions to patch the Projected File System component.

Proactive Monitoring: Monitor system logs for unusual process creation or access patterns that may indicate attempts to exploit local file system drivers.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced across the environment to limit the impact of an attacker gaining a foothold on a local system.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, particularly for systems where multiple users share access or where untrusted code might be executed locally. Administrators must prioritize the deployment of the vendor-supplied security updates to eliminate the underlying out-of-bounds read condition and prevent potential privilege escalation.

More Microsoft CVEs

Sources