CVE Vulnerabilities

CVE-2025-49694

NULL Pointer Dereference

Published: Jul 08, 2025 | Modified: Jul 15, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Null pointer dereference in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Windows_11_24h2Microsoft*10.0.26100.4652 (excluding)
Windows_server_2022_23h2Microsoft*10.0.25398.1732 (excluding)
Windows_server_2025Microsoft*10.0.26100.4652 (excluding)

Potential Mitigations

References