CVE-2025-62467: Windows Projected File System Elevation of Privilege Vulnerability
Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.
Other sources
Windows Projected File System Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2025Patch KB5071542 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6345Patch KB5071417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8146Patch KB5071544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4529Fixed in 10.0.20348.4467Patch KB5071413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62467?
CVE-2025-62467 is rated as a high-severity vulnerability due to its potential to allow an attacker to elevate privileges locally.
How do I fix CVE-2025-62467?
To fix CVE-2025-62467, ensure that all affected Windows updates have been applied as recommended by Microsoft.
What products are affected by CVE-2025-62467?
CVE-2025-62467 affects various versions of Windows 10, Windows 11, and Windows Server products.
Can I exploit CVE-2025-62467 remotely?
No, CVE-2025-62467 requires local access to exploit, making it a local privilege escalation vulnerability.
Who is vulnerable to CVE-2025-62467?
Any authorized user with access to affected versions of Windows operating systems may be vulnerable to CVE-2025-62467.