CVE-2025-55339

7.8

Microsoft · Windows

An out-of-bounds read vulnerability in the Windows NDIS component allows a locally authenticated attacker to elevate privileges on the affected system.

Executive summary

A local privilege escalation vulnerability in the Windows NDIS driver allows authenticated users to gain elevated system permissions.

Vulnerability

This is an out-of-bounds read flaw (CWE-125) within the Network Driver Interface Specification (NDIS) kernel component. It requires an attacker to have low-level local access to the system to trigger the vulnerability.

Business impact

Successful exploitation allows an attacker to escalate privileges from a standard user to a higher privilege level, potentially gaining full control over the local machine. With a CVSS score of 7.8, this vulnerability poses a significant risk to internal server security and workstation integrity, as it facilitates unauthorized lateral movement or the deployment of persistent malware.

Remediation

Immediate Action: Apply the October 2025 (or subsequent) Microsoft security updates to the affected Windows operating systems to patch the vulnerable NDIS component.

Proactive Monitoring: Monitor system audit logs for suspicious process creation or unusual attempts to interact with kernel-level drivers that may indicate exploitation attempts.

Compensating Controls: Ensure that access to local systems is strictly limited to authorized users and enforce the principle of least privilege to minimize the potential impact of local privilege escalation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for complete system compromise via privilege escalation, administrators should prioritize the deployment of the vendor-supplied security updates. While the requirement for local authentication reduces the attack surface, the risk remains high for multi-user environments and shared infrastructure. Ensure all affected Windows instances are patched within the standard maintenance window.

More Microsoft CVEs

Sources