VDB

GCVE-110-NCSC-2025-358

GCVE-110-NCSC-2025-358
Advisory PublishedCVSS 7.8/10
Vulnetix · Advisory published November 11, 2025
The document highlights a vulnerability in Windows Administrator Protection that allows an authorized attacker to locally escalate privileges due to an untrusted search path issue.

Weaknesses (CWE)

CWE-415Double FreeCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-201Insertion of Sensitive Information Into Sent DataCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-73External Control of File Name or PathCWE-284Improper Access ControlCWE-125Out-of-bounds ReadCWE-822Untrusted Pointer DereferenceCWE-325Missing Cryptographic StepCWE-416Use After FreeCWE-269Improper Privilege ManagementCWE-122Heap-based Buffer OverflowCWE-126Buffer Over-readCWE-532Insertion of Sensitive Information into Log FileCWE-426Untrusted Search PathCWE-270Privilege Context Switching Error

Risk Scores

CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C

Affected Products

VendorProductVersionsPlatforms
Microsoftvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,585 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›