CVE-2025-49680
published 2025-07-08CVE-2025-49680: Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
PriorityP338high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.47%
37.7th percentile
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.21073 | 10.0.10240.21073 |
| microsoft | windows_10_1607 | < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_10_1809 | < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_10_21h2 | < 10.0.19044.6093 | 10.0.19044.6093 |
| microsoft | windows_10_22h2 | < 10.0.19045.6093 | 10.0.19045.6093 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.21073 | 10.0.10240.21073 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.6093 | 10.0.19044.6093 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.6093 | 10.0.19045.6093 |
| microsoft | windows_11_22h2 | < 10.0.22621.5624 | 10.0.22621.5624 |
| microsoft | windows_11_23h2 | < 10.0.22631.5624 | 10.0.22631.5624 |
| microsoft | windows_11_24h2 | < 10.0.26100.4652 | 10.0.26100.4652 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5624 | 10.0.22621.5624 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5624 | 10.0.22631.5624 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5624 | 10.0.22631.5624 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.4652 | 10.0.26100.4652 |
| microsoft | windows_server_2016 | < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.8246 | 10.0.14393.8246 |
| microsoft | windows_server_2019 | < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.7558 | 10.0.17763.7558 |
| microsoft | windows_server_2022 | < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3932 | 10.0.20348.3932 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1732 | 10.0.25398.1732 |
| microsoft | windows_server_2025 | < 10.0.26100.4652 | 10.0.26100.4652 |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows Performance Recorder (WPR) Denial of Service Vulnerability
vendor_msrc·2025-07-08·CVSS 7.3
CVE-2025-49680 [HIGH] CWE-59 Windows Performance Recorder (WPR) Denial of Service Vulnerability
Windows Performance Recorder (WPR) Denial of Service Vulnerability
Description: Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
FAQ: According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
Exploitation of this attack requires a local attacker to create arbitrary directories. User interaction is necessary as the attacker relies on an Administrator to run wprui.exe for the first time.
Windows Performance Recorder: Windows Performance Recorder
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:E
GHSA
GHSA-pf5v-ggmj-v84g: Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally
ghsa_unreviewed·2025-07-08
CVE-2025-49680 [HIGH] CWE-59 GHSA-pf5v-ggmj-v84g: Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally
Improper link resolution before file access ('link following') in Windows Performance Recorder allows an authorized attacker to deny service locally.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-08
Published