CVE-2025-60705
7.8Microsoft · Windows
Improper access control in the Windows Client-Side Caching service allows a locally authenticated attacker to elevate privileges on the affected system.
Executive summary
A vulnerability in the Microsoft Windows Client-Side Caching service enables local privilege escalation, posing a significant risk to system integrity.
Vulnerability
This flaw is classified as an improper access control issue (CWE-284) within the Client-Side Caching (CSC) service. An attacker with low-level local user privileges can exploit this vulnerability to execute code or perform operations with elevated system permissions.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain elevated privileges, potentially leading to a full system compromise. With a CVSS score of 7.8, this vulnerability is considered High, as it enables a user to bypass local security boundaries, potentially resulting in unauthorized data access or the installation of malicious software.
Remediation
Immediate Action: Apply the relevant monthly security updates provided by Microsoft in the official security update guide to patch the vulnerable CSC service.
Proactive Monitoring: Review system event logs for unusual service activity or unexpected escalations of privilege originating from local user accounts.
Compensating Controls: Ensure the principle of least privilege is strictly enforced across the organization to limit the number of users who possess the local access required to trigger this vulnerability.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the High severity rating and the potential for full system compromise, administrators should prioritize the deployment of these security updates during the next maintenance cycle. Failure to remediate this issue leaves endpoints vulnerable to lateral movement or further compromise should an attacker gain an initial foothold on a local workstation.
More Microsoft CVEs
Sources
- Windows Client-Side Caching Elevation of Privilege Vulnerability Vendor advisory