CVE-2025-32718Heap-based Buffer Overflow in Microsoft Windows 10 Version 1507

Severity
7.8HIGHNVD
EPSS
1.0%
top 22.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages24 packages

NVDmicrosoft/windows< 10.0.14393.8148+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21034
NVDmicrosoft/windows_10_1607< 10.0.14393.8148
NVDmicrosoft/windows_10_1809< 10.0.17763.7434
NVDmicrosoft/windows_10_21h2< 10.0.19044.5965

🔴Vulnerability Details

2
CVEList
Windows SMB Client Elevation of Privilege Vulnerability2025-06-10
GHSA
GHSA-8gqq-cqfg-7f8m: Integer overflow or wraparound in Windows SMB allows an authorized attacker to elevate privileges locally2025-06-10

📋Vendor Advisories

1
Microsoft
Windows SMB Client Elevation of Privilege Vulnerability2025-06-10
CVE-2025-32718 — Heap-based Buffer Overflow | cvebase