CVE-2025-48803 - Missing Support for Integrity Check

Severity

67%

Complexity

8%

Confidentiality

98%

Missing support for integrity check in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to elevate privileges locally.

CVSS 3.1 Base Score 6.7. CVSS Attack Vector: local. CVSS Attack Complexity: low. CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

Demo Examples

Missing Support for Integrity Check

CWE-353

In this example, a request packet is received, and privileged information is sent to the requester:


               
}
outSock.send(sp);

The response containing secret data has no integrity check associated with it, allowing an attacker to alter the message without detection.

Overview

Type

Microsoft Windows Server

First reported 10 months ago

2025-07-08 17:15:00

Last updated 10 months ago

2025-07-15 14:31:00

Affected Software

Microsoft Windows Server 2016

Microsoft Windows Server 2019

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.