{"id":9116,"date":"2025-12-11T10:03:38","date_gmt":"2025-12-11T10:03:38","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/12\/11\/windows-defender-firewall-service-vulnerability-let-attackers-disclose-sensitive-data\/"},"modified":"2025-12-11T10:03:38","modified_gmt":"2025-12-11T10:03:38","slug":"windows-defender-firewall-service-vulnerability-let-attackers-disclose-sensitive-data","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/12\/11\/windows-defender-firewall-service-vulnerability-let-attackers-disclose-sensitive-data\/","title":{"rendered":"Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data"},"content":{"rendered":"<p>    Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems.<\/p>\n<p>The vulnerability, tracked as <a href=\"https:\/\/cybersecuritynews.com\/microsoft-december-2025-patch-tuesday\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-62468<\/a>, was assigned an Important severity rating and released on December 9, 2025.<\/p>\n<p>The flaw stems from an <a href=\"https:\/\/cybersecuritynews.com\/out-of-bounds-read-and-write\/\" target=\"_blank\" rel=\"noreferrer noopener\">out-of-bounds<\/a> read condition in the Windows Defender Firewall Service component.<\/p>\n<p>According to Microsoft\u2019s security advisory, an authorized attacker with high-level privileges can exploit this vulnerability to read portions of heap memory without user interaction.<\/p>\n<p>The vulnerability impacts the confidentiality of stored information but does not affect system integrity or availability. The vulnerability carries a CVSS v3.1 base score of 4.4.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">CVE ID<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CNA<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Impact<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">CVSS Score<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-62468<\/td>\n<td>Microsoft<\/td>\n<td>Information Disclosure<\/td>\n<td>4.4<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Classified with the following characteristics: local attack vector, low attack complexity, high privileges required, and no user interaction needed.<\/p>\n<p>Microsoft assessed the likelihood of exploitation as unlikely, with no public exploit code or active exploitation reported at the time of disclosure.<\/p>\n<p>Microsoft released security updates addressing CVE-2025-62468 across multiple <a href=\"https:\/\/cybersecuritynews.com\/malicious-pypi-package-mimics-as-socks5-proxy-tool\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows platforms<\/a>.<\/p>\n<p><strong>Affected Products\u00a0<\/strong><\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th class=\"has-text-align-left\" data-align=\"left\">Product<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">KB Article<\/th>\n<th class=\"has-text-align-left\" data-align=\"left\">Build Numbers<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Windows Server 2025<\/td>\n<td>KB5072033, KB5072014<\/td>\n<td>10.0.26100.7462 \/ 10.0.26100.7392<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 24H2 (x64)<\/td>\n<td>KB5072033, KB5072014<\/td>\n<td>10.0.26100.7462 \/ 10.0.26100.7392<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 24H2 (ARM64)<\/td>\n<td>KB5072033, KB5072014<\/td>\n<td>10.0.26100.7462 \/ 10.0.26100.7392<\/td>\n<\/tr>\n<tr>\n<td>Windows Server 2022 23H2 (Server Core)<\/td>\n<td>KB5071542<\/td>\n<td>10.0.25398.2025<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 23H2 (x64)<\/td>\n<td>KB5071417<\/td>\n<td>10.0.22631.6345<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 23H2 (ARM64)<\/td>\n<td>KB5071417<\/td>\n<td>10.0.22631.6345<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 25H2 (x64)<\/td>\n<td>KB5072033, KB5072014<\/td>\n<td>10.0.26200.7462 \/ 10.0.26200.7392<\/td>\n<\/tr>\n<tr>\n<td>Windows 11 Version 25H2 (ARM64)<\/td>\n<td>KB5072033, KB5072014<\/td>\n<td>10.0.26200.7462 \/ 10.0.26200.7392<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>The patches are available for Windows Server 2025, Windows Server 2022, Windows 11 Version 24H2, Windows 11 Version 25H2, and Windows 11 Version 23H2 on both x64 and ARM64-based systems.<\/p>\n<p>Organizations can obtain the necessary patches through <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-62468\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Microsoft Update<\/a> or the Microsoft Update Catalog. Windows Server 2025 and recent Windows 11 versions received two types of updates.<\/p>\n<p>Standard security updates and security <a href=\"https:\/\/cybersecuritynews.com\/wsus-patch-broken-hotpatching\/\" target=\"_blank\" rel=\"noreferrer noopener\">hotpatch<\/a> updates, allowing flexibility in deployment strategies. Administrators should promptly apply security updates to mitigate exposure risks.<\/p>\n<p>The vulnerability requires high-level <a href=\"https:\/\/cybersecuritynews.com\/zoom-rooms-for-windows-and-macos\/\" target=\"_blank\" rel=\"noreferrer noopener\">privilege escalation<\/a>, limiting the immediate threat scope. But underscores the importance of restricting administrative access and monitoring privileged user activities.<\/p>\n<p>The out-of-bounds read weakness (CWE-125) allows attackers to access memory regions beyond intended boundaries. Successfully exploiting this vulnerability requires membership in specific user groups with elevated permissions.<\/p>\n<p>Making this a targeted threat, primarily affecting organizations with strict access controls and privileged-user <a href=\"https:\/\/cybersecuritynews.com\/network-monitoring-tools\/\" target=\"_blank\" rel=\"noreferrer noopener\">monitoring protocols<\/a>.<\/p>\n<p>Security researchers from Kunlun Lab deserve credit for responsibly disclosing this vulnerability to Microsoft through coordinated disclosure channels.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/windows-defender-firewall-service-vulnerability\/\">Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/windows-defender-firewall-service-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems. The vulnerability, tracked as CVE-2025-62468, was assigned an Important severity rating and released on December 9, 2025. The flaw stems from an [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131,648,395],"tags":[130],"class_list":["post-9116","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","category-vulnerability-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9116"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9116"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9116\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9116"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9116"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9116"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}