CVE-2025-48799: Microsoft Windows 10 1607
High severity, CVSS 7.8. EPSS: 1.3% chance of exploitation in the next 30 days.
Improper link resolution before file access ('link following') in Windows Update Service allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Windows 10 1607: before 10.0.14393.8246 (fixed in 10.0.14393.8246)
- Microsoft Windows 10 1809: before 10.0.17763.7558 (fixed in 10.0.17763.7558)
- Microsoft Windows 10 21h2: before 10.0.19044.6093 (fixed in 10.0.19044.6093)
- Microsoft Windows 10 22h2: before 10.0.19045.6093 (fixed in 10.0.19045.6093)
- Microsoft Windows 11 22h2: before 10.0.22621.5624 (fixed in 10.0.22621.5624)
- Microsoft Windows 11 23h2: before 10.0.22631.5624 (fixed in 10.0.22631.5624)
- Microsoft Windows 11 24h2: before 10.0.26100.4652 (fixed in 10.0.26100.4652)
- Microsoft Windows Server 2025: before 10.0.26100.4652 (fixed in 10.0.26100.4652)
Published 2025-07-08. Last modified 2026-06-17.