VDB
CVE-2025-32706
CVE-2025-32706
PUBLISHED
KEV
Windows ist ein Betriebssystem von Microsoft. Windows Server 2016 ist ein Betriebssystem von Microsoft. Windows Server 2019 ist ein Betriebssystem von Microsoft.
EPSS 1.12% · 78.6th percentile
Risk Scores
EPSS Score
1.12%
78.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Microsoft Windows Server 2022 | |
| Microsoft | Microsoft Windows Server 2016 | |
| Microsoft | Microsoft Windows Server 2008 SP2 | |
| Microsoft | Microsoft Windows Remote Desktop client for Desktop | |
| Microsoft | Microsoft Windows Server 2022 23H2 Edition | |
| Microsoft | Microsoft Windows 10 Version 22H2 | |
| Microsoft | Microsoft Windows 11 Version 23H2 | |
| Microsoft | Microsoft Windows 10 Version 21H2 | |
| Microsoft | Microsoft Windows 10 Version 1607 | |
| Microsoft | Microsoft Windows Server Windows HLK for 2025 | |
| Microsoft | Microsoft Windows 10 HLK version 21H1 | |
| Microsoft | Microsoft Windows Server 2012 R2 | |
| Microsoft | Microsoft Windows 11 Version 24H2 | |
| Microsoft | Microsoft Windows 10 Version 1809 | |
| Microsoft | Microsoft Windows Server 2019 | |
| Microsoft | Microsoft Windows 10 | |
| Microsoft | Microsoft Windows Server 2008 R2 SP1 | |
| Microsoft | Microsoft Windows Server 2012 | |
| Microsoft | Microsoft Windows 11 HLK 22H2 | |
| Microsoft | Microsoft Windows Server 2025 |
…and 10 more
Exploit Intelligence
- https://www.microsoft.com/en-us/msrc/exploitability-index?rtc=1 (msrc)
- https://www.vicarius.io/vsociety/posts/cve-2025-32706-detection-script-elevation-of-privilege-vulnerability-in-microsoft-windows-common-log-file-system-driver (nist-nvd)
- https://www.vicarius.io/vsociety/posts/cve-2025-32706-mitigation-script-elevation-of-privilege-vulnerability-in-microsoft-windows-common-log-file-system-driver (nist-nvd)
- Windows Media Remote Code Execution Vulnerability (circl)
- CIRCL seen: CVE-2025-29840 (circl-sighting)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (Microsoft Windows) (gpz)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (Microsoft Windows) (gpz)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (Microsoft Windows) (gpz)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (Microsoft Windows) (gpz)
- Windows Common Log File System Driver Elevation of Privilege Vulnerability (Microsoft Windows) (gpz)
…and 31 more exploits
Timeline
- May 13, 2025 CISA KEV Added
- May 13, 2025 PoC Published
- May 13, 2025 CVE Published
- May 13, 2025 PoC Published
- May 14, 2025 EPSS Score
- May 16, 2025 EPSS Score
- May 17, 2025 EPSS Score
- May 25, 2025 EPSS Score
- May 31, 2025 Coalition ESS Score
- Jun 6, 2025 EPSS Score
- Jun 15, 2025 EPSS Score
- Jun 17, 2025 EPSS Score
References
- https://wid.cert-bund.de/.well-known/csaf/white/2025/wid-sec-w-2025-1050.json advisory
- https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2025-1050 advisory
- https://msrc.microsoft.com/update-guide/ advisory
- https://www.hitachi.com/products/it/storage-solutions/sec_info/2025/05.html advisory
- https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969?tab=readme-ov-file advisory