Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.

zetlyn/cve-nvd vulnerability cve CVE-2025-62461 cpe cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* cpe cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:* cpe cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* cpe cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* known 2025-12-09

https://nvd.nist.gov/vuln/detail/CVE-2025-62461

Properties

cvss7.8
receipt
Source
NVD
Its words
7.8
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.6691",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.6691",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Windows 11 Version 25H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26200.7462",
                "status": "affected",
                "version": "10.0.26200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.4529",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.2025",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8",
                "versionEndExcluding": "10.0.19044.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79",
                "versionEndExcluding": "10.0.19045.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01",
                "versionEndExcluding": "10.0.22631.6345",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67",
                "versionEndExcluding": "10.0.26200.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67",
                "versionEndExcluding": "10.0.20348.4467",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6",
                "versionEndExcluding": "10.0.25398.2025",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally."
      },
      {
        "lang": "es",
        "value": "Lectura excesiva de búfer en el controlador de filtro del sistema de archivos proyectado de Windows permite a un atacante autorizado elevar privilegios localmente."
      }
    ],
    "id": "CVE-2025-62461",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-62461",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-10T04:56:56.380386Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-09T18:15:57.680",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62461"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-126"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
productWindows 10 Version 1809
receipt
Source
NVD
Its words
Windows 10 Version 1809
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.6691",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.6691",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Windows 11 Version 25H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26200.7462",
                "status": "affected",
                "version": "10.0.26200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.4529",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.2025",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8",
                "versionEndExcluding": "10.0.19044.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79",
                "versionEndExcluding": "10.0.19045.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01",
                "versionEndExcluding": "10.0.22631.6345",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67",
                "versionEndExcluding": "10.0.26200.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67",
                "versionEndExcluding": "10.0.20348.4467",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6",
                "versionEndExcluding": "10.0.25398.2025",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally."
      },
      {
        "lang": "es",
        "value": "Lectura excesiva de búfer en el controlador de filtro del sistema de archivos proyectado de Windows permite a un atacante autorizado elevar privilegios localmente."
      }
    ],
    "id": "CVE-2025-62461",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-62461",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-10T04:56:56.380386Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-09T18:15:57.680",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62461"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-126"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
statusAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.6691",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.6691",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Windows 11 Version 25H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26200.7462",
                "status": "affected",
                "version": "10.0.26200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.4529",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.2025",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8",
                "versionEndExcluding": "10.0.19044.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79",
                "versionEndExcluding": "10.0.19045.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01",
                "versionEndExcluding": "10.0.22631.6345",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67",
                "versionEndExcluding": "10.0.26200.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67",
                "versionEndExcluding": "10.0.20348.4467",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6",
                "versionEndExcluding": "10.0.25398.2025",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally."
      },
      {
        "lang": "es",
        "value": "Lectura excesiva de búfer en el controlador de filtro del sistema de archivos proyectado de Windows permite a un atacante autorizado elevar privilegios localmente."
      }
    ],
    "id": "CVE-2025-62461",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-62461",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-10T04:56:56.380386Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-09T18:15:57.680",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62461"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-126"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}
vendorMicrosoft
receipt
Source
NVD
Its words
Microsoft
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "platforms": [
              "32-bit Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 1809",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 21H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19044.6691",
                "status": "affected",
                "version": "10.0.19044.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "32-bit Systems",
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 10 Version 22H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.19045.6691",
                "status": "affected",
                "version": "10.0.19045.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems"
            ],
            "product": "Windows 11 version 22H3",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 23H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.22631.6345",
                "status": "affected",
                "version": "10.0.22631.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "ARM64-based Systems",
              "x64-based Systems"
            ],
            "product": "Windows 11 Version 24H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "product": "Windows 11 Version 25H2",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26200.7462",
                "status": "affected",
                "version": "10.0.26200.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2019 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.17763.8146",
                "status": "affected",
                "version": "10.0.17763.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.20348.4529",
                "status": "affected",
                "version": "10.0.20348.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2022, 23H2 Edition (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.25398.2025",
                "status": "affected",
                "version": "10.0.25398.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          },
          {
            "platforms": [
              "x64-based Systems"
            ],
            "product": "Windows Server 2025 (Server Core installation)",
            "vendor": "Microsoft",
            "versions": [
              {
                "lessThan": "10.0.26100.7462",
                "status": "affected",
                "version": "10.0.26100.0",
                "versionType": "custom"
              }
            ]
          }
        ],
        "source": "secure@microsoft.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*",
                "matchCriteriaId": "5CEB496A-8AF3-458D-B466-16204E535DE0",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*",
                "matchCriteriaId": "C99D0580-E443-4440-A211-19BA3C2C4AFA",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "9D04167A-522C-433E-8CEB-C1D8A02C23D8",
                "versionEndExcluding": "10.0.19044.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A86D6CDC-55E5-4817-A6CE-4CE41921FB79",
                "versionEndExcluding": "10.0.19045.6691",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "6DCE32D0-A9E0-4029-AB35-5E202A42AF01",
                "versionEndExcluding": "10.0.22631.6345",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8DCD2A6E-7CD0-4FCC-AC11-5A1470776C24",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "8EA08CDD-D682-403D-8B50-879EB4D88C67",
                "versionEndExcluding": "10.0.26200.7392",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "A20DBDB1-D0DE-4800-8BEA-35EE5D53659D",
                "versionEndExcluding": "10.0.17763.8146",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "C552FBB4-8F98-492E-A084-AF14C9514A67",
                "versionEndExcluding": "10.0.20348.4467",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "E9CE4A36-DA42-40CC-8724-E30A22CA84B6",
                "versionEndExcluding": "10.0.25398.2025",
                "vulnerable": true
              },
              {
                "criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
                "matchCriteriaId": "35BBEADA-D039-479B-A1BA-B2A7E37235BE",
                "versionEndExcluding": "10.0.26100.7392",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ]
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally."
      },
      {
        "lang": "es",
        "value": "Lectura excesiva de búfer en el controlador de filtro del sistema de archivos proyectado de Windows permite a un atacante autorizado elevar privilegios localmente."
      }
    ],
    "id": "CVE-2025-62461",
    "lastModified": "2026-09-30T20:10:00.247",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "LOCAL",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 1.8,
          "impactScore": 5.9,
          "source": "secure@microsoft.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-62461",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-10T04:56:56.380386Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-09T18:15:57.680",
    "references": [
      {
        "source": "secure@microsoft.com",
        "tags": [
          "Vendor Advisory"
        ],
        "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-62461"
      }
    ],
    "sourceIdentifier": "secure@microsoft.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-126"
          }
        ],
        "source": "secure@microsoft.com",
        "type": "Secondary"
      }
    ]
  }
}

Text

Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally. Lectura excesiva de búfer en el controlador de filtro del sistema de archivos proyectado de Windows permite a un atacante autorizado elevar privilegios localmente.