Security Feature Bypass in Windows Security Zone Mapping by Microsoft
CVE-2025-27737
8.6HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
An improper input validation issue in Windows Security Zone Mapping allows an unauthorized attacker to exploit the system locally. This vulnerability enables the bypass of critical security features designed to maintain the integrity and protection of the operating environment. It is essential for users to be aware of this risk and apply any necessary updates provided by Microsoft to enhance security measures.
Affected Version(s)
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20978
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.7970
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.7137
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved