PT-2025-10811 · Microsoft · Windows

Skorikari

·

Published

2025-03-11

·

Updated

2025-07-03

·

CVE-2025-24061

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows 10 Version 1809 Windows versions prior to the patch released on 2025-03-11
Description A security-feature bypass vulnerability in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature locally. This issue is related to a failure in the protection mechanism, enabling attackers to affect the system. The vulnerability may allow an attacker to bypass existing security restrictions and gain access to encrypted data.
Recommendations For Windows 10 Version 1809, apply the patch released on 2025-03-11 to resolve the issue. For Windows versions prior to the patch released on 2025-03-11, update to a version that includes the fix for this vulnerability. As a temporary workaround, consider restricting access to sensitive data and implementing additional security measures to minimize the risk of exploitation.

Fix

Protection Mechanism Failure

Weakness Enumeration

Related Identifiers

BDU:2025-02758
CVE-2025-24061

Affected Products

Windows