CVE-2025-32721Link Following in Microsoft Windows 10 Version 1507

CWE-59Link Following5 documents5 sources
Severity
7.3HIGHNVD
EPSS
0.7%
top 28.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 1.3 | Impact: 5.9

Affected Packages22 packages

NVDmicrosoft/windows< 10.0.14393.8148+4
NVDmicrosoft/windows_10_1507< 10.0.10240.21034
NVDmicrosoft/windows_10_1607< 10.0.14393.8148
NVDmicrosoft/windows_10_1809< 10.0.17763.7434
NVDmicrosoft/windows_10_21h2< 10.0.19044.5965

🔴Vulnerability Details

2
GHSA
GHSA-5mw4-49p3-cwrw: Improper link resolution before file access ('link following') in Windows Recovery Driver allows an authorized attacker to elevate privileges locally2025-06-10
CVEList
Windows Recovery Driver Elevation of Privilege Vulnerability2025-06-10

📋Vendor Advisories

1
Microsoft
Windows Recovery Driver Elevation of Privilege Vulnerability2025-06-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-32721 — Link Following in Microsoft | cvebase