CVE-2025-49666
published 2025-07-08CVE-2025-49666: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
PriorityP347high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
1.15%
63.4th percentile
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2016 | < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2019 | < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2022 | < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1732 | 10.0.25398.1732 |
| microsoft | windows_server_2025 | < 10.0.26100.4652 | 10.0.26100.4652 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.4652 | 10.0.26100.4652 |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability
vendor_msrc·2025-07-08·CVSS 7.2
CVE-2025-49666 [HIGH] CWE-122 Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability
Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
To successfully exploit this vulnerability, an attacker or the targeted user would need to achieve a high level of control over a machine, as the attack requires access to processes typically restricted from average users.
Essentially, the exploitation necessitates elevated privileges on the compromised machine due to the requirement of manipulating processes beyond the reach of standard user permissions.
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Customer Action
GHSA
GHSA-jmhj-j4mm-pjj6: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network
ghsa_unreviewed·2025-07-08
CVE-2025-49666 [HIGH] CWE-122 GHSA-jmhj-j4mm-pjj6: Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network
Heap-based buffer overflow in Windows Kernel allows an authorized attacker to execute code over a network.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published