CVE-2025-33069Improper Verification of Cryptographic Signature in Microsoft Windows 11 Version 24h2

Severity
5.1MEDIUMNVD
EPSS
0.6%
top 29.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.5 | Impact: 2.5

Affected Packages7 packages

NVDmicrosoft/windows< 10.0.26100.4270
NVDmicrosoft/windows_11_24h2< 10.0.26100.4270
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.4349
CVEListV5microsoft/windows_11_version_24h210.0.26100.010.0.26100.4349

🔴Vulnerability Details

1
GHSA
GHSA-4mqg-7w7j-8x9r: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature local2025-06-10

📋Vendor Advisories

1
Microsoft
Windows App Control for Business Security Feature Bypass Vulnerability2025-06-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-33069 — Microsoft vulnerability | cvebase