Back

HIGH

Windows Update Service Elevation of Privilege Vulnerability

Published Jul 8, 2025

Description

Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner microsoft
Published Jul 8, 2025
Updated Feb 13, 2026
Reserved May 26, 2025

CISA Vulnrichment

Updated Jul 8, 2025

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner microsoft
Published Jul 8, 2025
Updated Feb 13, 2026

GitHub

No data