CVE-2025-47181
published 2025-05-22CVE-2025-47181: Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
PriorityP350high8.8CVSS 3.1
AVLACLPRLUINSCCHIHAH
EPSS
0.49%
39.3th percentile
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | edge_update | < 1.3.195.61 | 1.3.195.61 |
| microsoft | microsoft_edge_updater | >= 1.0.0.0 < 1.3.195.61 | 1.3.195.61 |
| msrc | microsoft_edge_updater | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3rx-6qww-mhm3: Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges
ghsa_unreviewed·2025-05-23
CVE-2025-47181 [HIGH] CWE-59 GHSA-m3rx-6qww-mhm3: Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges
Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
Microsoft
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
vendor_msrc·2025-05-13·CVSS 8.8
CVE-2025-47181 [HIGH] CWE-59 Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability
Description: Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.
FAQ: According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?
An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.
FAQ: How could an attacker exploit this vulnerability?
To exploit this vulnerability, an attacker would first have to log on to the system. An a
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-05-22
Published