CVE-2025-47181

HIGH

Microsoft Edge Update < 1.3.195.61 - Authenticated Privilege Escalation via Improper Link Resolution

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-47181. PoCs published by encrypter15.

AI-analyzed exploit summary This repository provides a detailed technical analysis and conceptual model of CVE-2025-47181, a privilege escalation vulnerability in Microsoft Edge (Chromium-based) due to improper link resolution (CWE-59). It includes a Python script that simulates the attack mechanism but does not contain actual exploit code.

Description

Improper link resolution before file access ('link following') in Microsoft Edge (Chromium-based) allows an authorized attacker to elevate privileges locally.

Exploits (1)

nomisec WRITEUP 5 stars
by encrypter15 · poc
https://github.com/encrypter15/CVE-2025-47181

This repository provides a detailed technical analysis and conceptual model of CVE-2025-47181, a privilege escalation vulnerability in Microsoft Edge (Chromium-based) due to improper link resolution (CWE-59). It includes a Python script that simulates the attack mechanism but does not contain actual exploit code.

Classification
Writeup 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Theoretical
Target: Microsoft Edge (Chromium-based)
Auth required
Prerequisites: Local access to the system · Standard user privileges
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 8.8
EPSS 0.0049
EPSS Percentile 38.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (1)
microsoft/edge_update < 1.3.195.61
Published May 22, 2025
Tracked Since Feb 18, 2026