TGViewer
Vulnerability Management and more Vulnerability Management and more @avleonovcom · 2.89K subscribers
Post #1569 716
About Elevation of Privilege - Windows Update Service (CVE-2025-48799) vulnerability. This vulnerability is from the July Microsoft Patch Tuesday. Improper link resolution before file access ('link following') in the Windows Update Service allows an authorized attacker to elevate privileges to "NT AUTHORITY\SYSTEM".

🛠 An exploit for this vulnerability was published by researcher Filip Dragović (Wh04m1001) on July 8, the day of MSPT. In the exploit description, he states that the vulnerability affects Windows 10/11 systems with at least two hard drives. If the installation location for new apps is changed to the secondary drive (using Storage Sense), then during the installation of a new app, the wuauserv service will arbitrarily delete folders without checking for symbolic links, leading to to LPE.

🎞 In the demonstration video, Filip Dragović runs the EXE file and gets an administrator console.

👾 No signs of exploitation in the wild yet.

На русском

@avleonovcom #Microsoft #Windows #wuauserv #StorageSense
More from @avleonovcom
  1. Sep 14, 2026About Authentication Bypass - Microsoft SharePoint (CVE-2026-55040) vulnerability. SharePo…
  2. Sep 11, 2026About Elevation of Privilege - Windows Ancillary Function Driver for WinSock (CVE-2026-688…
  3. Sep 9, 2026September Microsoft Patch Tuesday. A total of 973 vulnerabilities were addressed - more th…
  4. Sep 7, 2026About Remote Code Execution - TeamCity (CVE-2026-63077) vulnerability. TeamCity is a propr…
  5. Sep 4, 2026About Remote Code Execution - TrueConf Server (CVE-2026-72529, CVE-2026-72530) vulnerabili…
  6. Aug 31, 2026About Remote Code Execution - Zimbra Collaboration (CVE-2026-73570) vulnerability. Zimbra…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →