CVE-2025-47987: Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
Other sources
Heap-based buffer overflow in Windows Cred SSProvider Protocol allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47987?
CVE-2025-47987 has been categorized as a critical vulnerability due to its potential for privilege escalation.
How do I fix CVE-2025-47987?
To remediate CVE-2025-47987, users should apply the latest security patches provided by Microsoft for the affected products.
Which Microsoft products are affected by CVE-2025-47987?
CVE-2025-47987 affects various Microsoft products including Windows Server 2012, 2016, 2019, and specific versions of Windows 10 and Windows 11.
Can CVE-2025-47987 be exploited remotely?
No, CVE-2025-47987 requires local access to exploit the heap-based buffer overflow.
What type of vulnerability is CVE-2025-47987?
CVE-2025-47987 is classified as a heap-based buffer overflow vulnerability under the Credential Security Support Provider Protocol.