CVE-2025-33069 — Improper Verification of Cryptographic Signature in Microsoft Windows 11 Version 24h2
Severity
5.1MEDIUMNVD
EPSS
0.6%
top 29.26%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 10
Description
Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature locally.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:NExploitability: 2.5 | Impact: 2.5
Affected Packages7 packages
🔴Vulnerability Details
1GHSA▶
GHSA-4mqg-7w7j-8x9r: Improper verification of cryptographic signature in App Control for Business (WDAC) allows an unauthorized attacker to bypass a security feature local↗2025-06-10