
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62455 is a local privilege escalation vulnerability caused by improper input validation in Windows Message Queuing (MSMQ). An authorized local attacker with low-level privileges can exploit this flaw to elevate privileges on the affected system without requiring user interaction. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday. Affected products span a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2) and Windows Server 2008, 2012, 2016, and 2019. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The root cause is classified as CWE-20 (Improper Input Validation) within the Windows Message Queuing (MSMQ) service. The attack vector is local, requiring an authenticated user with low privileges to submit maliciously crafted input to the MSMQ component, which fails to properly validate it before processing. No user interaction is required, and attack complexity is low, making exploitation straightforward for any local user account. No public technical write-ups or proof-of-concept code detailing the specific exploitation mechanics have been identified at this time (Microsoft MSRC).
Successful exploitation allows an attacker with low-privileged local access to gain elevated — potentially SYSTEM-level — privileges on the affected Windows host, resulting in high impact to confidentiality, integrity, and availability. This could enable an attacker to install malware, access sensitive data, modify system configurations, or disable security controls. The vulnerability affects a broad range of Windows environments, including both workstations and servers, increasing the potential scope of impact across enterprise environments (Microsoft MSRC).
Microsoft released security updates on December 9, 2025, addressing this vulnerability across all affected platforms. Administrators should apply the relevant cumulative updates to bring affected systems to the following minimum versions: Windows 10 1607/Server 2016 to build 10.0.14393.8688, Windows 10 1809/Server 2019 to build 10.0.17763.8146, Windows 10 21H2 to build 10.0.19044.6691, Windows 10 22H2 to build 10.0.19045.6691, Windows Server 2012 to build 6.2.9200.25815, Windows Server 2012 R2 to build 6.3.9600.22920, Windows Server 2008 SP2 to build 6.0.6003.23666, and Windows Server 2008 R2 SP1 to build 6.1.7601.28064. As an additional mitigation, organizations should enforce least-privilege principles, restrict local user access, and consider disabling the MSMQ service if it is not required (Microsoft MSRC).
CVE-2025-62455 was covered as part of broader December 2025 Patch Tuesday roundups by several security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with CVE-2025-62455 being one of the non-zero-day privilege escalation issues (BleepingComputer). Sophos and Zero Day Initiative also published Patch Tuesday review posts covering the December release (Sophos, ZDI). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."