CVE-2025-32722Improper Access Control in Microsoft Windows 10 Version 1507

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 30.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages24 packages

NVDmicrosoft/windows< 10.0.14393.8148+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21034
NVDmicrosoft/windows_10_1607< 10.0.14393.8148
NVDmicrosoft/windows_10_1809< 10.0.17763.7434
NVDmicrosoft/windows_10_21h2< 10.0.19044.5965

🔴Vulnerability Details

2
GHSA
GHSA-r68q-hvfv-hjmc: Improper access control in Windows Storage Port Driver allows an authorized attacker to disclose information locally2025-06-10
CVEList
Windows Storage Port Driver Information Disclosure Vulnerability2025-06-10

📋Vendor Advisories

1
Microsoft
Windows Storage Port Driver Information Disclosure Vulnerability2025-06-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-32722 — Improper Access Control in Microsoft | cvebase