PT-2025-28516 · Microsoft · Windows

Guhe120

+1

·

Published

2025-07-08

·

Updated

2025-07-17

·

CVE-2025-47981

CVSS v3.1
10
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Windows versions (affected versions not specified)

**Description:**

A critical vulnerability exists in the Windows SPNEGO Extended Negotiation (NEGOEX) security mechanism. This flaw is a heap-based buffer overflow that allows an unauthorized attacker to execute code remotely over a network. The vulnerability is considered 'wormable', meaning it has the potential to spread automatically across networks, similar to WannaCry and NotPetya. Successful exploitation grants attackers complete system control with SYSTEM privileges.

**Recommendations:**

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-08224
CVE-2025-47981

Affected Products

Windows