Privilege Escalation in Microsoft Brokering File System
CVE-2025-49693

7.8HIGH

What is CVE-2025-49693?

A noted vulnerability in Microsoft Brokering File System involves a double free error, potentially allowing an authorized attacker to elevate their privileges locally. This flaw highlights significant risks associated with local exploitation, emphasizing the need for users to apply available security updates and maintain robust security practices.

Affected Version(s)

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.5624

Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22631.5624

Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.5624

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49693 : Privilege Escalation in Microsoft Brokering File System