PT-2025-31360 · Microsoft · Windows

Published

2025-07-29

·

Updated

2026-01-30

·

CVE-2025-25011

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions versions prior to 2025 (affected versions not specified)
Description An uncontrolled search path element vulnerability can lead to local privilege escalation (LPE) via insecure directory permissions. Improper handling of directory permissions allows a local attacker to move and delete arbitrary files, potentially gaining SYSTEM privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2025-09241
CLEANSTART-2026-OJ15484
CVE-2025-25011

Affected Products

Windows