CVE-2025-62468
vulnerability analysis and mitigation

Overview

CVE-2025-62468 is an out-of-bounds read vulnerability in the Windows Defender Firewall Service that allows an authorized local attacker to disclose sensitive system information. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects Windows 11 versions 23H2, 24H2, and 25H2, as well as Windows Server 2025 and Windows Server 2022 23H2 Edition. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, though ENISA rates it at 4.4 (Microsoft MSRC, BleepingComputer).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers), occurring within the Windows Defender Firewall Service. An attacker with low-privilege local access (per NVD CVSS) — or high-privilege access per ENISA's scoring — can trigger the out-of-bounds read condition without requiring user interaction, causing the service to read memory beyond its allocated buffer boundaries. This memory disclosure could expose sensitive contents of the firewall service's process memory. No public technical write-up detailing the precise vulnerable code path or a working proof-of-concept exploit has been confirmed (Microsoft MSRC, ZDI Blog).

Impact

Successful exploitation results in an information disclosure impact, specifically a high confidentiality impact with no integrity or availability consequences. An attacker who exploits this vulnerability could read sensitive memory contents from the Windows Defender Firewall Service process, potentially exposing credentials, configuration data, or other privileged information resident in memory. The scope is limited to the local system, and there is no evidence of direct lateral movement capability, though disclosed memory contents could facilitate further attacks (Microsoft MSRC, GBHackers, eSecurity Planet).

Mitigation and workarounds

Microsoft released security updates on December 9, 2025, addressing this vulnerability across all affected platforms. Administrators should apply the following patched builds: Windows 11 23H2 → 10.0.22631.6345 or later; Windows 11 24H2 / Windows Server 2025 → 10.0.26100.7392 or later (ENISA references 10.0.26100.7462); Windows 11 25H2 → 10.0.26200.7392 or later; Windows Server 2022 23H2 → 10.0.25398.2025 or later. As a general hardening measure, organizations should enforce least-privilege principles to limit local account access and monitor high-privilege account activity on systems running the Windows Defender Firewall Service (Microsoft MSRC, Lansweeper).

Community reactions

The vulnerability received moderate coverage as part of the broader December 2025 Patch Tuesday roundup, which addressed 57 flaws including 3 zero-days. Security outlets including BleepingComputer, GBHackers, CyberSecurityNews, and eSecurity Planet covered the flaw specifically in the context of Windows Defender Firewall memory disclosure. Sophos and Zero Day Initiative (ZDI) included it in their Patch Tuesday review summaries. Community discussion on Reddit's CVEWatch subreddit listed it among trending CVEs for December 12–13, 2025, though overall sentiment treated it as a moderate-severity issue given its local-only attack vector (BleepingComputer, Sophos, ZDI Blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management