CVE-2025-33075Link Following in Microsoft Windows 10 Version 1507

CWE-59Link Following4 documents4 sources
Severity
7.8HIGHNVD
EPSS
1.2%
top 21.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages26 packages

NVDmicrosoft/windows< 10.0.14393.8148+5
NVDmicrosoft/windows_10_1507< 10.0.10240.21034
NVDmicrosoft/windows_10_1607< 10.0.14393.8148
NVDmicrosoft/windows_10_1809< 10.0.17763.7434
NVDmicrosoft/windows_10_21h2< 10.0.19044.5965

🔴Vulnerability Details

2
CVEList
Windows Installer Elevation of Privilege Vulnerability2025-06-10
GHSA
GHSA-vvqg-cgqr-c8gc: Improper link resolution before file access ('link following') in Windows Installer allows an authorized attacker to elevate privileges locally2025-06-10

📋Vendor Advisories

1
Microsoft
Windows Installer Elevation of Privilege Vulnerability2025-06-10
CVE-2025-33075 — Link Following in Microsoft | cvebase