
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62468 is an out-of-bounds read vulnerability in the Windows Defender Firewall Service that allows an authorized local attacker to disclose sensitive system information. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects Windows 11 versions 23H2, 24H2, and 25H2, as well as Windows Server 2025 and Windows Server 2022 23H2 Edition. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) per NVD, though ENISA rates it at 4.4 (Microsoft MSRC, BleepingComputer).
The root cause is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers), occurring within the Windows Defender Firewall Service. An attacker with low-privilege local access (per NVD CVSS) — or high-privilege access per ENISA's scoring — can trigger the out-of-bounds read condition without requiring user interaction, causing the service to read memory beyond its allocated buffer boundaries. This memory disclosure could expose sensitive contents of the firewall service's process memory. No public technical write-up detailing the precise vulnerable code path or a working proof-of-concept exploit has been confirmed (Microsoft MSRC, ZDI Blog).
Successful exploitation results in an information disclosure impact, specifically a high confidentiality impact with no integrity or availability consequences. An attacker who exploits this vulnerability could read sensitive memory contents from the Windows Defender Firewall Service process, potentially exposing credentials, configuration data, or other privileged information resident in memory. The scope is limited to the local system, and there is no evidence of direct lateral movement capability, though disclosed memory contents could facilitate further attacks (Microsoft MSRC, GBHackers, eSecurity Planet).
Microsoft released security updates on December 9, 2025, addressing this vulnerability across all affected platforms. Administrators should apply the following patched builds: Windows 11 23H2 → 10.0.22631.6345 or later; Windows 11 24H2 / Windows Server 2025 → 10.0.26100.7392 or later (ENISA references 10.0.26100.7462); Windows 11 25H2 → 10.0.26200.7392 or later; Windows Server 2022 23H2 → 10.0.25398.2025 or later. As a general hardening measure, organizations should enforce least-privilege principles to limit local account access and monitor high-privilege account activity on systems running the Windows Defender Firewall Service (Microsoft MSRC, Lansweeper).
The vulnerability received moderate coverage as part of the broader December 2025 Patch Tuesday roundup, which addressed 57 flaws including 3 zero-days. Security outlets including BleepingComputer, GBHackers, CyberSecurityNews, and eSecurity Planet covered the flaw specifically in the context of Windows Defender Firewall memory disclosure. Sophos and Zero Day Initiative (ZDI) included it in their Patch Tuesday review summaries. Community discussion on Reddit's CVEWatch subreddit listed it among trending CVEs for December 12–13, 2025, though overall sentiment treated it as a moderate-severity issue given its local-only attack vector (BleepingComputer, Sophos, ZDI Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."