CVE-2025-47956
BaseFortify
Publication date: 2025-06-10
Last updated on: 2025-07-09
Assigner: Microsoft Corporation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| microsoft | windows_security_app | to 1000.27840.0.1000 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability involves external control of a file name or path in the Windows Security App, which allows an authorized attacker to perform local spoofing. Essentially, an attacker with some level of access can manipulate file names or paths to deceive users or the system locally.
How can this vulnerability impact me? :
The vulnerability can impact you by enabling an authorized attacker to spoof content or interfaces locally, potentially misleading users or security mechanisms. This could lead to confusion or misinterpretation of security information, although it does not directly affect system integrity or availability.