CVE-2025-62467

7.8

Microsoft · Windows Projected File System

An integer overflow vulnerability in the Windows Projected File System allows a locally authorized attacker to elevate privileges to the system level.

Executive summary

A critical integer overflow vulnerability in the Windows Projected File System permits an authenticated local attacker to achieve privilege escalation, posing a significant risk to host integrity.

Vulnerability

This flaw involves an integer overflow or wraparound condition within the Windows Projected File System. A local attacker with low-level privileges can trigger this vulnerability to execute code or gain unauthorized elevated access to the host machine.

Business impact

Successful exploitation allows an attacker who already has local access to gain elevated privileges, potentially leading to full system compromise. Given the CVSS score of 7.8, this vulnerability is considered High severity, as it facilitates unauthorized control over sensitive system resources and data. This could result in significant operational disruption, data exfiltration, or the deployment of persistent threats within the environment.

Remediation

Immediate Action: Administrators must apply the latest monthly security updates provided by Microsoft to all affected Windows systems.

Proactive Monitoring: Review system and security event logs for anomalous process creation or unauthorized attempts to access system-level files associated with the Projected File System.

Compensating Controls: Ensure that local user permissions follow the principle of least privilege to minimize the potential impact if a local account is compromised.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability represents a significant risk for local privilege escalation within Windows environments. Organizations should prioritize the deployment of the vendor-supplied security updates to all identified endpoints. Consistent patch management cycles are essential to mitigate the risk posed by this and similar local escalation vectors.

More Microsoft CVEs

Sources