CVE-2025-53142Use After Free in Microsoft Windows 11 Version 22h2

CWE-416Use After Free8 documents6 sources
Severity
7.0HIGHNVD
EPSS
0.1%
top 84.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages9 packages

NVDmicrosoft/windows< 10.0.25398.1791+1
NVDmicrosoft/windows_11_22h2< 10.0.22621.5768
NVDmicrosoft/windows_11_23h2< 10.0.22631.5768
NVDmicrosoft/windows_11_24h2< 10.0.26100.4851
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.4946

🔴Vulnerability Details

2
CVEList
Microsoft Brokering File System Elevation of Privilege Vulnerability2025-08-12
GHSA
GHSA-crvv-j87g-j7hr: Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally2025-08-12

📋Vendor Advisories

2
Microsoft
Microsoft Brokering File System Elevation of Privilege Vulnerability2025-08-12
Microsoft
initramfs: avoid filename buffer overrun2024-12-10

🕵️Threat Intelligence

3
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review | Qualys2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review2025-08-12
CVE-2025-53142 — Use After Free in Microsoft | cvebase