Description
Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9Attack Vector: Local
Complexity: High
Privileges: Low
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages9 packages
🔴Vulnerability Details
2CVEListMicrosoft Brokering File System Elevation of Privilege Vulnerability↗2025-08-12 ▶ GHSAGHSA-crvv-j87g-j7hr: Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally↗2025-08-12 ▶ 📋Vendor Advisories
2MicrosoftMicrosoft Brokering File System Elevation of Privilege Vulnerability↗2025-08-12 ▶ Microsoftinitramfs: avoid filename buffer overrun↗2024-12-10 ▶ 🕵️Threat Intelligence
3BleepingcomputerMicrosoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws↗2025-08-12 ▶ QualysMicrosoft and Adobe Patch Tuesday, August 2025 Security Update Review | Qualys↗2025-08-12 ▶ QualysMicrosoft and Adobe Patch Tuesday, August 2025 Security Update Review↗2025-08-12 ▶