CVE-2025-54104: Windows Defender Firewall Service Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Defender Firewall Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54104?
CVE-2025-54104 is categorized as an Elevation of Privilege vulnerability in Windows Defender Firewall Service.
How do I fix CVE-2025-54104?
To fix CVE-2025-54104, apply the appropriate security updates released by Microsoft for your affected Windows version.
What systems are affected by CVE-2025-54104?
CVE-2025-54104 affects multiple versions of Windows Server, Windows 10, and Windows 11.
Can CVE-2025-54104 be exploited remotely?
CVE-2025-54104 requires local access, meaning exploitation cannot be achieved remotely.
What are the potential impacts of CVE-2025-54104?
Successful exploitation of CVE-2025-54104 can allow an attacker to elevate their privileges on the affected system.