- Description
 - Microsoft Brokering File System Elevation of Privilege Vulnerability
 - Source
 - secure@microsoft.com
 - NVD status
 - Analyzed
 - Products
 - windows_11_24h2, windows_server_2022_23h2, windows_server_2025
 
CVSS 3.1
- Type
 - Primary
 - Base score
 - 7.8
 - Impact score
 - 6
 - Exploitability score
 - 1.1
 - Vector string
 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
 - Severity
 - HIGH
 
- secure@microsoft.com
 - CWE-416
 - nvd@nist.gov
 - NVD-CWE-noinfo
 
- Hype score
 - Not currently trending
 
[
  {
    "nodes": [
      {
        "negate": false,
        "cpeMatch": [
          {
            "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "78A3F671-95DC-442A-A511-1E875DF93546",
            "versionEndExcluding": "10.0.26100.2894"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "E3E0C061-2DA7-4237-9607-F6792DC92DD3",
            "versionEndExcluding": "10.0.25398.1369"
          },
          {
            "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
            "vulnerable": true,
            "matchCriteriaId": "155593BE-9192-4286-81F7-2C66B55B0438",
            "versionEndExcluding": "10.0.26100.2894"
          }
        ],
        "operator": "OR"
      }
    ]
  }
]