CVE-2025-47956: Microsoft Windows Security App

Medium severity, CVSS 5.5. EPSS: 0.7% chance of exploitation in the next 30 days.

External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.

Affected products

  • Microsoft Windows Security App: before 1000.27840.0.1000 (fixed in 1000.27840.0.1000)

Published 2025-06-10. Last modified 2026-06-17.