CVE-2025-62462
7.8Microsoft · Windows Projected File System
A buffer over-read vulnerability exists in the Windows Projected File System that allows an authorized local attacker to achieve privilege escalation.
Executive summary
A buffer over-read vulnerability in the Windows Projected File System allows an authenticated local attacker to gain elevated privileges on affected Windows systems.
Vulnerability
This is a buffer over-read flaw (CWE-126) occurring within the Windows Projected File System. The vulnerability requires the attacker to be an authorized, low-privileged user on the local system to trigger the flaw.
Business impact
Successful exploitation allows a low-privileged local user to escalate their permissions to a higher level, potentially gaining administrative control over the host system. Given the CVSS score of 7.8, this vulnerability poses a significant risk to organizational security, as it could facilitate further lateral movement or unauthorized data access within the network.
Remediation
Immediate Action: Apply the relevant monthly security updates provided by Microsoft for the specific Windows version and build number in use.
Proactive Monitoring: Review local system logs for unusual process execution patterns or unauthorized attempts to interact with protected file system drivers.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced on all workstations and servers to limit the number of users who could potentially initiate an attack.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Organizations should prioritize the deployment of the official Microsoft security patches to all affected Windows endpoints. Due to the potential for full privilege escalation, testing and deploying these updates in accordance with standard patch management cycles is essential to prevent local attackers from compromising system integrity.