CVE-2025-55317

7.8

Microsoft · AutoUpdate (MAU)

Microsoft AutoUpdate (MAU) is vulnerable to improper link resolution before file access, which can be exploited by an authorized local attacker to achieve privilege escalation.

Executive summary

A vulnerability in Microsoft AutoUpdate allows local attackers to elevate privileges, posing a significant risk to system integrity and administrative control.

Vulnerability

This flaw involves improper link resolution (CWE-59), where the application fails to safely handle symbolic links before accessing files. An attacker with local access and low privileges can leverage this behavior to escalate their permissions to a higher level.

Business impact

Successful exploitation allows an attacker to gain elevated privileges on the host system, which could lead to full system compromise. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk that could facilitate unauthorized data access, persistence, or the deployment of further malicious payloads within the environment.

Remediation

Immediate Action: Update Microsoft AutoUpdate to version 4.80 or later to ensure the link resolution flaw is corrected.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized attempts to modify system files associated with the update service.

Compensating Controls: Restrict local user permissions where possible and ensure that non-administrative users cannot access sensitive directories that might be targeted by link-following attacks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The potential for privilege escalation makes this a critical update for all environments utilizing Microsoft products on macOS. Organizations should prioritize the deployment of the vendor-supplied patch to all endpoints to eliminate the risk of local privilege escalation. Continued vigilance regarding system access and user privilege management remains essential to prevent exploitation of this and similar local attack vectors.

More Microsoft CVEs

Sources