Brokering File System Elevation of Privilege Vulnerability in Microsoft Products
CVE-2025-21372

7.8HIGH

Summary

This vulnerability affects Microsoft's Brokering File System, allowing an attacker with limited access to elevate their privileges on the system. Successful exploitation could enable unauthorized access to sensitive data or functions that should be restricted. It is essential for users and administrators to apply the recommended security updates to mitigate the risks associated with this vulnerability.

Affected Version(s)

Windows 11 Version 24H2 ARM64-based Systems 10.0.26100.0 < 10.0.26100.2894

Windows Server 2022, 23H2 Edition (Server Core installation) x64-based Systems 10.0.25398.0 < 10.0.25398.1369

Windows Server 2025 (Server Core installation) x64-based Systems 10.0.26100.0 < 10.0.26100.2894

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.