Brokering File System Elevation of Privilege Vulnerability in Microsoft Products
CVE-2025-21372
7.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 January 2025
Summary
This vulnerability affects Microsoft's Brokering File System, allowing an attacker with limited access to elevate their privileges on the system. Successful exploitation could enable unauthorized access to sensitive data or functions that should be restricted. It is essential for users and administrators to apply the recommended security updates to mitigate the risks associated with this vulnerability.
Affected Version(s)
Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.2894
Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 < 10.0.25398.1369
Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.2894
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved