CVE-2025-62467
vulnerability analysis and mitigation

Overview

CVE-2025-62467 is an integer overflow or wraparound vulnerability in the Windows Projected File System (ProjFS) that allows an authorized local attacker to elevate privileges. It was disclosed by Microsoft on December 9, 2025, as part of the December 2025 Patch Tuesday security update release. Affected products span a wide range of Windows versions including Windows 10 (21H2, 22H2, 1809), Windows 11 (23H2, 24H2, 25H2), Windows Server 2019, 2022, 2022 23H2, and Windows Server 2025. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (MSRC Advisory, Feedly).

Technical details

The root cause is classified under CWE-190 (Integer Overflow or Wraparound) and CWE-126 (Buffer Over-read), occurring within the Windows Projected File System (ProjFS) driver component. An attacker with a low-privilege local account can trigger the integer overflow condition, potentially causing memory corruption that leads to privilege escalation — a pattern consistent with CAPEC-92 (Forced Integer Overflow). The attack vector is local, requires low privileges, no user interaction, and has low attack complexity, making it straightforward to exploit once an attacker has authenticated access to the system (MSRC Advisory, Feedly).

Impact

Successful exploitation grants a low-privileged attacker full elevation of privileges on the affected Windows system, with high impact to confidentiality, integrity, and availability. An attacker could execute arbitrary code with elevated (e.g., SYSTEM-level) privileges, access sensitive data, modify system configurations, or establish persistent footholds for lateral movement within a network. The broad scope of affected Windows versions — including both client and server editions — significantly widens the potential attack surface in enterprise environments (MSRC Advisory, Feedly).

Mitigation and workarounds

Microsoft released patches for all affected Windows versions on December 9, 2025, as part of the December 2025 Patch Tuesday update. Administrators should apply the relevant cumulative updates to bring systems to the following minimum build versions: Windows 10 21H2 → 10.0.19044.6691, Windows 10 22H2 → 10.0.19045.6691, Windows 10 1809 / Server 2019 → 10.0.17763.8146, Windows Server 2022 → 10.0.20348.4467, Windows Server 2022 23H2 → 10.0.25398.2025, Windows 11 23H2 → 10.0.22631.6345, Windows 11 24H2 / Server 2025 → 10.0.26100.7392, Windows 11 25H2 → 10.0.26200.7392. As interim measures, organizations should enforce least-privilege access controls and monitor for suspicious privileged activity on unpatched systems (MSRC Advisory, Feedly).

Community reactions

CVE-2025-62467 was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the December 2025 update addressed 57 flaws including 3 zero-days, with this vulnerability included among the batch (BleepingComputer). The Zero Day Initiative published a December 2025 security update review covering the patch cycle (ZDI Blog). Sophos and SANS ISC also published Patch Tuesday summaries referencing the update (Sophos News, SANS ISC). No notable individual researcher commentary or significant social media discussion specific to this CVE was identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management