PT-2025-28533 · Microsoft · Windows Update Service +3

Filip Dragović

+1

·

Published

2024-09-03

·

Updated

2025-07-16

·

CVE-2025-48799

CVSS v3.1
7.8
VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

**Name of the Vulnerable Software and Affected Versions:**

Windows versions prior to July 8, 2025

**Description:**

An improper link resolution vulnerability exists in the Windows Update Service before file access. This allows an authorized attacker to elevate privileges locally. The vulnerability affects Windows clients (Windows 10 and Windows 11) with at least two hard drives. The issue involves incorrect handling of symbolic links during file access, potentially allowing an attacker to perform arbitrary file deletion and escalate privileges to the SYSTEM level.

**Recommendations:**

Update Windows to a version released on or after July 8, 2025.

Exploit

Fix

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-08180
CVE-2025-48799

Affected Products

Windows
Windows 10
Windows 11
Windows Update Service