CVE-2025-48799
HIGH 7.8EPSS 1.0%
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 1.05% chance of exploitation in the next 30 days, 62th percentile
- Published
- 2025-07-08
- Updated
- 2026-02-13
Proof-of-concept exploits (5)
- https://www.vicarius.io/vsociety/posts/cve-2025-48799-detection-script-elevation-of-privi…
- https://www.vicarius.io/vsociety/posts/cve-2025-48799-mitigation-script-elevation-of-priv…
- Wh04m1001/CVE-2025-48799268★ · 2025-07-08
- painoob/CVE-2025-487990★ · 2025-08-05
- gmh5225/CVE-2025-48799-