Link following in Microsoft Windows and Windows Server - CVE-2025-48799
Published: July 9, 2025 / Updated: September 24, 2025
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue in Windows Update Service. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
Affected software
Windows Server
How to mitigate CVE-2025-48799
Windows Server - addressed in versions 2022 23H2 10.0.22621.5472, 2025 10.0.26100.4652
Links to Public Exploits and PoC-codes
- Exploit #11982 - CVE-2025-48799 (September 24, 2025)
- Exploit #11902 - CVE-2025-48799 (CVE-2025-48799 reveals a remote code execution flaw in Apache Tomcat 9.0.48 caused by an integer overflow in the HTTP header parser. The article explains how attackers can exploit the X-Forwarded header to inject shellcode.) (August 30, 2025)
- Exploit #11854 - CVE-2025-48799 (August 15, 2025)
- Exploit #11783 - CVE-2025-48799 (July 18, 2025)