PT-2025-28612 · Microsoft · Windows

R4Nger

+1

·

Published

2025-07-08

·

Updated

2025-07-09

·

CVE-2025-49723

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows (affected versions not specified)
Description: The issue concerns missing authorization in the Windows StateRepository API, allowing an authorized attacker to perform local tampering. This means that an attacker with certain privileges can manipulate the system locally due to the lack of proper authorization checks in the API.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-08330
CVE-2025-49723

Affected Products

Windows