CVE-2025-62461
7.8Microsoft · Windows Projected File System Filter Driver
A buffer over-read vulnerability in the Windows Projected File System Filter Driver enables local authenticated users to achieve privilege escalation.
Executive summary
A buffer over-read vulnerability in the Microsoft Windows Projected File System Filter Driver allows locally authenticated attackers to escalate privileges to a higher level of authority.
Vulnerability
This vulnerability is a buffer over-read (CWE-126) located within the Windows Projected File System Filter Driver. An attacker must already possess local, low-level authenticated access to the system to trigger this flaw and execute the necessary operations to elevate their privileges.
Business impact
The ability for a standard user to escalate privileges poses a significant risk to organizational security, as it allows attackers to bypass standard access controls. With elevated permissions, an attacker could potentially install malware, modify system configurations, or access sensitive data that was previously restricted, leading to full system compromise. Given the CVSS score of 7.8, this flaw represents a high-severity risk that requires prompt attention to maintain the integrity of host environments.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to patch the vulnerable driver.
Proactive Monitoring: Monitor system logs for unusual process creation or unauthorized attempts to access protected system files that typically require administrative privileges.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced across all user accounts to minimize the potential impact of a local privilege escalation attempt.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize the deployment of the identified Microsoft security updates to affected Windows systems. Because this vulnerability facilitates privilege escalation, it serves as a critical link in the attack chain for local threats, and timely remediation is necessary to prevent potential lateral movement or persistent compromise of host assets.