CVE-2025-33069
published 2025-06-10CVE-2025-33069: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
PriorityP423medium5.1CVSS 3.1
AVLACLPRNUINSUCLILAN
EPSS
0.29%
20.6th percentile
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_11_24h2 | < 10.0.26100.4270 | 10.0.26100.4270 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4349 | 10.0.26100.4349 |
| microsoft | windows_server_2025 | < 10.0.26100.4270 | 10.0.26100.4270 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.4349 | 10.0.26100.4349 |
| msrc | windows_11_version_24h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_24h2_for_x64-based_systems | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.15.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_msrc5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4mqg-7w7j-8x9r: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature local
ghsa_unreviewed·2025-06-10
CVE-2025-33069 [MEDIUM] CWE-347 GHSA-4mqg-7w7j-8x9r: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature local
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
Microsoft
Windows App Control for Business Security Feature Bypass Vulnerability
vendor_msrc·2025-06-10·CVSS 5.1
CVE-2025-33069 [MEDIUM] CWE-347 Windows App Control for Business Security Feature Bypass Vulnerability
Windows App Control for Business Security Feature Bypass Vulnerability
Description: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
FAQ: What kind of security feature could be bypassed by successfully exploiting this vulnerability?
An attacker can spoof the signature to get it to bypass App Control policy.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L), and integrity (I:L) but lead to no loss of availability (A:N). What is the impact of this vulnerability?
An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality), make changes to disclosed inform
No detection rules found.
No public exploits indexed.
2025-06-10
Published