PT-2025-28631 · Microsoft · Windows Storage +1

Ron Ben Yizhak

+1

·

Published

2025-07-08

·

Updated

2025-08-11

·

CVE-2025-49760

CVSS v2.0
4.0
VectorAV:N/AC:L/Au:S/C:P/I:N/A:N

**Name of the Vulnerable Software and Affected Versions:**

Windows versions (affected versions not specified)

**Description:**

A spoofing vulnerability exists in Windows Storage due to improper external control of a file name or path. This allows an authorized attacker to perform spoofing attacks over a network. The vulnerability affects the core RPC system, potentially enabling attackers to impersonate trusted services, including Windows Defender. This could lead to domain privilege escalation through EPM poisoning.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-08307
CVE-2025-49760

Affected Products

Windows
Windows Storage