CVE-2025-64673
7.8Microsoft · Windows
A local privilege escalation vulnerability exists in the Storvsp.sys driver for Microsoft Windows, allowing authorized users to gain elevated system privileges.
Executive summary
A local privilege escalation vulnerability in the Windows Storvsp.sys driver allows an authenticated attacker to gain elevated system privileges, posing a significant risk to host integrity.
Vulnerability
This vulnerability is classified as improper access control within the Storvsp.sys driver. It allows an attacker who has already achieved local authenticated access to the system to bypass security restrictions and escalate their privileges.
Business impact
The ability for a low privileged user to escalate to higher system privileges represents a severe security risk. This could allow an attacker to bypass critical security controls, install persistent malware, or access sensitive data that should be restricted. With a CVSS score of 7.8, this vulnerability is categorized as High severity, necessitating prompt remediation to prevent unauthorized system control.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the December 2025 update cycle to patch the vulnerable Storvsp.sys driver.
Proactive Monitoring: Audit system logs for unexpected privilege escalation events, such as unauthorized service creation or unusual process execution patterns associated with standard user accounts.
Compensating Controls: Ensure robust endpoint detection and response (EDR) solutions are active to identify and block suspicious local process behaviors that deviate from baseline user activities.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for complete system compromise, administrators should prioritize the deployment of the security updates for the affected Windows versions. Testing and verification of the patch should be conducted in accordance with standard internal change management policies to ensure stability, followed by rapid organization-wide deployment.
More Microsoft CVEs
Sources
- Windows Storage VSP Driver Elevation of Privilege Vulnerability Vendor advisory