CVE-2025-49689

Published Jul 8, 2025

Last updated 3 days ago

CVSS high 7.8
Microsoft
VHDX

Overview

AI description

Automated description summarized from trusted sources.

CVE-2025-49689 is an integer overflow or wraparound vulnerability found in Microsoft Windows Virtual Hard Disk (VHDX). It allows an unauthorized attacker to elevate privileges locally on a targeted system. The vulnerability arises from a calculation that can result in an integer overflow or wraparound, potentially leading to weaknesses in resource management or execution control. User interaction is required to exploit this vulnerability. A security update was released on July 8, 2025, to address the vulnerability across multiple Windows versions.

Description
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
Source
secure@microsoft.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
7.8
Impact score
5.9
Exploitability score
1.8
Vector string
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secure@microsoft.com
CWE-125

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.