Security Vulnerability Report
中文
CVE-2025-62467 CVSS 7.8 HIGH

CVE-2025-62467

Published: 2025-12-09 18:15:59
Last Modified: 2025-12-12 20:04:06

Description

Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally.

CVSS Details

CVSS Score
7.8
Severity
HIGH
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Configurations (Affected Products)

cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* - VULNERABLE
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* - VULNERABLE
Windows 10 1507
Windows 10 1607
Windows 10 1703
Windows 10 1803
Windows 10 1809
Windows 10 1903
Windows 10 1909
Windows 10 2004
Windows 10 20H2
Windows 10 21H1
Windows 10 21H2
Windows 10 22H2
Windows 11 21H2
Windows 11 22H2
Windows 11 23H2
Windows Server 2016
Windows Server 2019
Windows Server 2022

PoC / Exploit Code

⚠ For Security Research Only
The following code is for security research and authorized testing only.
python
# CVE-2025-62467 PoC - Windows Projected File System Integer Overflow # This PoC demonstrates triggering the integer overflow condition # Actual exploitation requires advanced kernel debugging skills import ctypes from ctypes import wintypes import struct # Windows API definitions kernel32 = ctypes.windll.kernel32 ntdll = ctypes.windll.ntdll # Projected File System GUID PROJFS_GUID = '{0D9A7536-1C90-4E5E-9F1B-5C5A5B5E9F1B}' def create_projected_directory(target_path): """Create a Projected File System directory for testing""" try: # Enable ProjFS via Windows API # This is a simplified PoC - full exploitation requires kernel-level manipulation print(f"[*] Attempting to create Projected FS at: {target_path}") # Trigger conditions that may lead to integer overflow # In real exploitation, this would involve: # 1. Creating multiple virtual files with specific attributes # 2. Manipulating file size values to cause integer wraparound # 3. Exploiting the overflow in buffer allocation # Simulated trigger - actual PoC requires kernel debugging malicious_size = 0xFFFFFFFFFFFFFFFF # Potential overflow trigger print(f"[*] Setting projected file size to trigger overflow: {hex(malicious_size)}") print(f"[!] This requires kernel-mode debugging to confirm overflow") print(f"[!] Successful exploitation leads to EoP from low-privilege to SYSTEM") return True except Exception as e: print(f"[-] Error: {e}") return False def verify_vulnerability(): """Verify if system is vulnerable""" print("[*] CVE-2025-62467 Vulnerability Check") print("[*] Target: Windows Projected File System (ProjFS)") print("[*] Vulnerability: Integer overflow in file size handling") print("[*] Impact: Local Privilege Escalation") print("") # Check Windows version version = ctypes.c_ulong() kernel32.GetVersionExW(ctypes.byref(version)) print(f"[*] Windows Version: {version.value & 0xFF}.{(version.value >> 8) & 0xFF}") print("[*] Checking for ProjFS support...") return True if __name__ == "__main__": verify_vulnerability() create_projected_directory("C:\\TestProjectedFS") print(" [!] Note: This PoC is for educational purposes only.") print("[!] Actual exploitation requires kernel debugging tools.")

References

Raw JSON Data

JSON
{"cve": {"id": "CVE-2025-62467", "sourceIdentifier": "[email protected]", "published": "2025-12-09T18:15:58.727", "lastModified": "2025-12-12T20:04:05.743", "vulnStatus": "Analyzed", "cveTags": [], "descriptions": [{"lang": "en", "value": "Integer overflow or wraparound in Windows Projected File System allows an authorized attacker to elevate privileges locally."}], "metrics": {"cvssMetricV31": [{"source": "[email protected]", "type": "Secondary", "cvssData": {"version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "baseScore": 7.8, "baseSeverity": "HIGH", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH"}, "exploitabilityScore": 1.8, "impactScore": 5.9}]}, "weaknesses": [{"source": "[email protected]", "type": "Secondary", "description": [{"lang": "en", "value": "CWE-126"}, {"lang": "en", "value": "CWE-190"}]}], "configurations": [{"nodes": [{"operator": "OR", "negate": false, "cpeMatch": [{"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.19044.6691", "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.19045.6691", "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.22631.6345", "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26100.7392", "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26200.7392", "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.17763.8146", "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.20348.4467", "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.25398.2025", "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6"}, {"vulnerable": true, "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.26100.7392", "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE"}]}]}], "references": [{"url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62467", "source": "[email protected]", "tags": ["Vendor Advisory"]}]}}