CVE-2025-47161
HIGHMicrosoft Defender For Endpoint - Improper Access Control
Title source: ruleDescription
Improper access control in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
Exploits (1)
Scores
CVSS v3
7.8
EPSS
0.0581
EPSS Percentile
90.5%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-284
Status
published
Products (1)
microsoft/defender_for_endpoint
< 101.25022.0002
Published
May 15, 2025
Tracked Since
Feb 18, 2026