PT-2025-28512 · Microsoft · Windows Ssdp Service+1

K0Shl

·

Published

2025-07-08

·

Updated

2025-07-09

·

CVE-2025-47975

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows SSDP Service (affected versions not specified)
Description: The issue concerns a double free in the Windows SSDP Service, which allows an authorized attacker to elevate privileges locally. This means an attacker with certain permissions can exploit this issue to gain higher levels of access to the system.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Double Free

Weakness Enumeration

Related Identifiers

BDU:2025-08445
CVE-2025-47975

Affected Products

Windows
Windows Ssdp Service