PT-2025-31359 · Microsoft · Windows

Published

2025-07-29

·

Updated

2025-07-31

·

CVE-2025-0712

CVSS v3.1
7.0
VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions:

(affected versions not specified)

Description:

An uncontrolled search path element vulnerability can lead to local privilege escalation (LPE) via insecure directory permissions. The vulnerability arises from improper handling of directory permissions. An attacker with local access may exploit this flaw to move and delete arbitrary files, potentially gaining SYSTEM privileges.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2025-09240
CVE-2025-0712

Affected Products

Windows