Important CVSS 7.8 EPSS 0.03627 🔬 Patch diffed 2025-02 archive

Executive Summary

None

Overview

7.8
CVSS HIGH
Important
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
Category Elevation of Privilege
Released Feb 11 2025
Last Updated Feb 11 2025
Publicly Disclosed No
CISA KEV Not Listed
Known Exploits None Known
EPSS Score 0.03627 — 0.8833 percentile
NVD CVSS 7.8 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.8

EPSS Score

0.03627
probability of exploitation in the next 30 days
0.8833 percentile - updated 2026-07-25
View on FIRST.org

Affected Products

25 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5052040 (Security Update) Important Elevation of Privilege Yes
Windows 10 for x64-based Systems 5052040 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for 32-bit Systems 5052006 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1607 for x64-based Systems 5052006 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for 32-bit Systems 5052000 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 1809 for x64-based Systems 5052000 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for 32-bit Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for ARM64-based Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 21H2 for x64-based Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for 32-bit Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for ARM64-based Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 10 Version 22H2 for x64-based Systems 5051974 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 22H2 for ARM64-based Systems 5051989 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 22H2 for x64-based Systems 5051989 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for ARM64-based Systems 5051989 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 23H2 for x64-based Systems 5051989 (Security Update) Important Elevation of Privilege Yes
Windows 11 Version 24H2 for ARM64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Elevation of Privilege 5050009 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows 11 Version 24H2 for x64-based Systems 5051987 (Security Update) 5052105 (SecurityHotpatchUpdate) Important Elevation of Privilege 5050009 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.26100.3194 10.0.26100.3107 Yes None Windows Server 2012 5052020 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 (Server Core installation) 5052020 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 5052042 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2012 R2 (Server Core installation) 5052042 (Monthly Rollup) Important Elevation of Privilege Yes
Windows Server 2016 5052006 (Security Update) Important Elevation of Privilege Yes
Windows Server 2016 (Server Core installation) 5052006 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 5052000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2019 (Server Core installation) 5052000 (Security Update) Important Elevation of Privilege Yes
Windows Server 2022 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Elevation of Privilege 5049983 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022 (Server Core installation) 5051979 (Security Update) 5052106 (SecurityHotpatchUpdate) Important Elevation of Privilege 5049983 Base: 7.8 Temporal: 6.8 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C 10.0.20348.3207 10.0.20348.3148 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5051980 (Security Update) Important Elevation of Privilege Yes

Patches

8 patches
Article Type Restart
5052040 Security Update Yes
5052006 Security Update Yes
5052000 Security Update Yes
5051974 Security Update Yes
5051989 Security Update Yes
5052020 Monthly Rollup Yes
5052042 Monthly Rollup Yes
5051980 Security Update Yes

Patch Diff

ghidriff · cleanmgr.exe (KB5051987)

cleanmgr.exe (run by the privileged SilentCleanup task) gains a SetProcessMitigationPolicy(ProcessRedirectionTrustPolicy=0x10) call in WinMainT, enabling Redirection Guard so the kernel refuses to follow attacker-planted junctions during cleanup. This severs the arbitrary folder-contents-delete -> C:\Config.msi -> SYSTEM EoP primitive (CWE-59 link following). Gated behind WIL CFR Feature_3318489400; the call hard-fails the process if the policy cannot be applied. The import itself is absent from the vulnerable 1882 build.

Pre-patch version 10.0.26100.1882 Download
Post-patch version 10.0.26100.3194 Download
Function Address Change Note
__GSHandlerCheck 1400122e4 -> 140016034 refcount, address similarity 1.0
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> 1400038d8 -> 140003a44 refcount, address, calling similarity 1.0
wil::details_abi::SemaphoreValue::CreateFromValueInternal 140003c1c -> 140003d4c refcount, address, calling, called similarity 0.98
wil::details::WilFailureNotifyWatchers 140005afc -> 140005c7c code, length, address similarity 0.89
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::reset 140005c78 -> 140005e00 refcount, address, calling similarity 1.0
wil::mutex_t<class_wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::CloseHandle(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,0>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>,struct_wil::err_returncode_policy>::acquire 140005ba0 -> 140005d28 refcount, address, calling similarity 1.0
wil::details::GetLastErrorFailHr 1400042b8 -> 140004428 refcount, address, calling similarity 1.0
operator_delete 140005dc4 -> 140006620 refcount, address, calling similarity 1.0
wil::details::in1diag3::FailFast_Unexpected 140003d44 -> 140003e9c code, length, address similarity 0.86
wil::last_error_context::last_error_context 140003738 -> 140003834 refcount, address, calling similarity 1.0
MSVCRT.DLL::memcpy_s EXTERNAL:00000028 -> EXTERNAL:0000002b refcount, address, calling similarity 1.0
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::AcquireSRWLockExclusive EXTERNAL:00000074 -> EXTERNAL:00000070 refcount, address, calling similarity 1.0
atexit 140002920 -> 140002a20 refcount, address, calling similarity 1.0
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::HeapFree EXTERNAL:0000005c -> EXTERNAL:0000005d refcount, address, calling similarity 1.0
wil::TraceLoggingProvider::Initialize 140008890 -> 14000a020 refcount, address similarity 1.0
StringCchPrintfW 14000570c -> 14000581c refcount, address, calling similarity 1.0
API-MS-WIN-CORE-PROCESSTHREADS-L1-1-0.DLL::GetCurrentProcessId EXTERNAL:00000058 -> EXTERNAL:00000056 refcount, address, calling similarity 1.0
wil::details::in1diag3::Return_Hr 140005358 -> 140005418 refcount, address, calling similarity 1.0
wil::details_abi::ProcessLocalStorage<struct_wil::details_abi::ProcessLocalData>::~ProcessLocalStorage<struct_wil::details_abi::ProcessLocalData> 140003764 -> 140003860 code, length, address, called similarity 0.2
_purecall 1400071c0 -> 14000a660 refcount, address similarity 1.0
API-MS-WIN-CORE-HEAP-L1-1-0.DLL::GetProcessHeap EXTERNAL:0000005a -> EXTERNAL:0000005e refcount, address, calling similarity 1.0
WinMainT 140006614 -> 14000955c code, length, address, called similarity 0.25
wil::details_abi::ProcessLocalStorageData<struct_wil::details_abi::ProcessLocalData>::Acquire 140003964 -> 140003ad0 code, length, address, called similarity 0.63
wil::details::FreeProcessHeap 140003dc0 -> 140003f30 refcount, address, calling similarity 0.9
wil::details::ProcessHeapAlloc 140004f78 -> 1400050e8 refcount, address, calling similarity 1.0
wil::details_abi::SemaphoreValue::~SemaphoreValue 140003918 -> 140003a84 refcount, address, calling similarity 1.0
wil::details::unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::ReleaseMutex(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,2>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<void*___ptr64,void_(__cdecl*)(void*___ptr64)_noexcept,&void___cdecl_wil::details::ReleaseMutex(void*___ptr64),struct_wistd::integral_constant<unsigned___int64,2>,void*___ptr64,void*___ptr64,0,std::nullptr_t>_> 1400038f8 -> 140003a64 refcount, address, calling similarity 1.0
USER32.DLL::LoadIconW EXTERNAL:00000016 refcount, calling similarity 1.0
wil::details::ReportFailure_Hr<3> 1400032f8 -> 1400033f8 code, refcount, length, address, calling similarity 0.84
wil_details_GetNtDllProcedureAddress 140005d60 -> 140005f44 refcount, address, calling similarity 0.91
wil::last_error_context::~last_error_context 140003940 -> 140003aac refcount, address, calling similarity 1.0
__security_check_cookie 1400123c0 -> 140016110 refcount, address, calling similarity 1.0
wil::details::`dynamic_initializer_for_'g_header_init_WilInitialize_ResultMacros_DesktopOrSystem'' 1400024d0 code, length similarity 0.95
memset 140012376 -> 1400160d2 refcount, address, calling similarity 0.89
API-MS-WIN-CORE-SYNCH-L1-1-0.DLL::CreateMutexExW EXTERNAL:00000077 -> EXTERNAL:0000007b refcount, address, calling similarity 1.0
wil::details::unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_>::~unique_storage<struct_wil::details::resource_policy<struct__RTL_SRWLOCK*___ptr64,void_(__cdecl*)(struct__RTL_SRWLOCK*___ptr64),&void___cdecl_ReleaseSRWLockExclusive(struct__RTL_SRWLOCK*___ptr64),struct_wistd::integral_constant<unsigned___int64,1>,struct__RTL_SRWLOCK*___ptr64,struct__RTL_SRWLOCK*___ptr64,0,std::nullptr_t>_> 140009a20 -> 14000635c refcount, address, calling similarity 1.0
__chkstk 140012480 -> 1400161d0 refcount, address, calling similarity 1.0
_guard_dispatch_icall$thunk$10345483385596137414 140013010 -> 140017010 refcount, address, calling similarity 0.89
wil_details_GetKernelBaseProcAddress 140005ccc -> 140005ea8 code, refcount, length, address, calling similarity 0.94
wistd::__throw_bad_function_call 140005b74 -> 140005cfc name, fullname, refcount, sig, address, calling, parent similarity 1.0
wil::details_abi::SemaphoreValue::TryGetPointer 140005818 -> 140005928 code, name, fullname, refcount, length, sig, address, calling, called similarity 0.15
wil::details::FeatureImpl<struct___WilFeatureTraits_Feature_3318489400>::__private_IsEnabled 1400071e8 -> 140009fe4 code, name, fullname, refcount, length, sig, address, calling, called, parent similarity 0.29
View full diff report View RCA report Download PoC

Known Exploits

Acknowledgments

None