
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62458 is a heap-based buffer overflow vulnerability in the Windows Win32K graphics (GRFX) component that allows a locally authenticated, low-privileged attacker to elevate privileges on affected systems. It was published on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. Affected products span a wide range of Windows versions, including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 23H2, Windows Server 2008 R2 SP1, 2012, 2012 R2, 2016, 2019, and 2022. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is a heap-based buffer overflow (CWE-122) in the Win32K GRFX subsystem, a kernel-mode graphics component responsible for rendering operations in Windows. An attacker with low-privileged local access can trigger the overflow through crafted graphics-related operations, causing memory corruption that can be leveraged to execute code in a higher-privilege context. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once local access is obtained. The vulnerability is associated with CAPEC-92 (Forced Integer Overflow) as a related attack pattern (Microsoft MSRC, Feedly).
Successful exploitation allows a low-privileged local attacker to gain full administrative (SYSTEM-level) control over the affected Windows system, resulting in high confidentiality, integrity, and availability impact. An attacker could execute arbitrary code with elevated privileges, access sensitive data, install malware, create new privileged accounts, or disable security controls. In environments where attackers have already obtained initial access (e.g., via phishing or a separate vulnerability), this flaw could serve as a critical stepping stone for lateral movement and full domain compromise (Microsoft MSRC, Feedly).
Microsoft released patches for CVE-2025-62458 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Organizations should apply the relevant cumulative updates to bring affected systems to the following minimum build versions: Windows 10 21H2 → 10.0.19044.6691, Windows 10 22H2 → 10.0.19045.6691, Windows 10 1607/Server 2016 → 10.0.14393.8688, Windows 10 1809/Server 2019 → 10.0.17763.8146, Windows 11 23H2 → 10.0.22631.6345, Windows Server 2022 → 10.0.20348.4467. As interim measures, organizations should enforce least-privilege principles, restrict local user account access, and monitor for unusual privilege escalation activity (Microsoft MSRC, Feedly).
CVE-2025-62458 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Tenable noted it among the 56 CVEs addressed in the December 2025 update cycle, and the Zero Day Initiative published a review of the December 2025 security updates that included this vulnerability (Tenable Blog, ZDI Blog). Qualys and Sophos also covered the December Patch Tuesday in their respective blogs, noting the breadth of the update (Qualys Blog, Sophos News). Community and social media reactions were limited, with no significant independent researcher commentary specifically focused on this CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."