Новости компьютерной безопасности:

  Latest News

Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

С сайта: Vulnerability(cybersecuritynews.com)

Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges

Author: Guru Baran

Microsoft has addressed four elevation of privilege vulnerabilities in its Windows Defender Firewall service, all rated as “Important” in severity.

The security flaws were detailed in Microsoft’s September 9, 2025, security update release. If exploited, these vulnerabilities could allow an authenticated attacker to gain higher privileges on an affected system.

The four vulnerabilities are tracked as CVE-2025-53808, CVE-2025-54104, CVE-2025-54109, and CVE-2025-54915. All four enable a local attacker to escalate their privileges, posing a significant risk to system integrity.

At the time of disclosure, Microsoft stated that none of the vulnerabilities had been publicly disclosed or actively exploited in the wild.

Windows Defender Firewall Vulnerabilities
Three of the four vulnerabilities (CVE-2025-54104, CVE-2025-54109, and CVE-2025-54915) are caused by a “type confusion” flaw within the Windows Defender Firewall Service.

Type confusion is a common class of memory safety bug where a program attempts to access a resource with an incompatible type, leading to unexpected and often insecure behavior. In this case, it allows an authorized attacker to trigger a condition that leads to local privilege escalation.

The fourth vulnerability, CVE-2025-53808, is also a service elevation of privilege flaw, though Microsoft’s advisory does not specify it as a type confusion bug.

The common thread among all four is the potential outcome: a low-privileged user gaining elevated system rights.

To exploit any of these vulnerabilities, an attacker must first have authenticated access to the target machine. Furthermore, exploitation requires the attacker’s account to be a member of a specific, restricted user group.

This high prerequisite is reflected in the CVSS metric “Privileges Required: High (PR:H),” indicating that a casual or unauthenticated attacker cannot leverage these flaws.

A successful exploit would allow the attacker to elevate their privileges from a “Medium Integrity Level” to “Local Service.”

While not full system or administrator-level control, gaining Local Service privileges provides significant capabilities, allowing an attacker to access and manipulate a wide range of system resources, install malicious software, or further compromise the affected host.

Mitigations
Microsoft’s exploitability assessment indicates that an attack is “Less Likely” for CVE-2025-53808, CVE-2025-54104, and CVE-2025-54109.

For CVE-2025-54915, the assessment is even lower, at “Exploitation Unlikely.” This analysis is based on the high privileges required for an attacker to be in a position to exploit the flaws.

Despite the low likelihood of exploitation, the “Important” severity rating underscores the potential danger if an attacker meets the necessary prerequisites.

Microsoft has released security updates to patch these vulnerabilities across all affected versions of Windows.

System administrators and users are strongly advised to apply the September 2025 security updates promptly to protect their systems and mitigate the risk of potential privilege escalation attacks.



#Cyber_Security #Cyber_Security_News #Vulnerability #Windows #cyber_security #cyber_security_news #vulnerability

Оригинальная версия на сайте: Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.