Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

Posted on December 11, 2025December 11, 2025 By CWS

A vital data disclosure vulnerability in Home windows Defender Firewall Service, which may permit licensed attackers to entry delicate heap reminiscence on affected methods.

The vulnerability, tracked as CVE-2025-62468, was assigned an Necessary severity score and launched on December 9, 2025.

The flaw stems from an out-of-bounds learn situation within the Home windows Defender Firewall Service part.

In keeping with Microsoft’s safety advisory, a certified attacker with high-level privileges can exploit this vulnerability to learn parts of heap reminiscence with out person interplay.

The vulnerability impacts the confidentiality of saved data however doesn’t have an effect on system integrity or availability. The vulnerability carries a CVSS v3.1 base rating of 4.4.

CVE IDCNAImpactCVSS ScoreCVE-2025-62468MicrosoftInformation Disclosure4.4

Labeled with the next traits: native assault vector, low assault complexity, excessive privileges required, and no person interplay wanted.

Microsoft assessed the chance of exploitation as unlikely, with no public exploit code or energetic exploitation reported on the time of disclosure.

Microsoft launched safety updates addressing CVE-2025-62468 throughout a number of Home windows platforms.

Affected Merchandise 

ProductKB ArticleBuild NumbersWindows Server 2025KB5072033, KB507201410.0.26100.7462 / 10.0.26100.7392Windows 11 Model 24H2 (x64)KB5072033, KB507201410.0.26100.7462 / 10.0.26100.7392Windows 11 Model 24H2 (ARM64)KB5072033, KB507201410.0.26100.7462 / 10.0.26100.7392Windows Server 2022 23H2 (Server Core)KB507154210.0.25398.2025Windows 11 Model 23H2 (x64)KB507141710.0.22631.6345Windows 11 Model 23H2 (ARM64)KB507141710.0.22631.6345Windows 11 Model 25H2 (x64)KB5072033, KB507201410.0.26200.7462 / 10.0.26200.7392Windows 11 Model 25H2 (ARM64)KB5072033, KB507201410.0.26200.7462 / 10.0.26200.7392

The patches can be found for Home windows Server 2025, Home windows Server 2022, Home windows 11 Model 24H2, Home windows 11 Model 25H2, and Home windows 11 Model 23H2 on each x64 and ARM64-based methods.

Organizations can get hold of the required patches by Microsoft Replace or the Microsoft Replace Catalog. Home windows Server 2025 and up to date Home windows 11 variations acquired two varieties of updates.

Customary safety updates and safety hotpatch updates, permitting flexibility in deployment methods. Directors ought to promptly apply safety updates to mitigate publicity dangers.

The vulnerability requires high-level privilege escalation, limiting the rapid menace scope. However underscores the significance of limiting administrative entry and monitoring privileged person actions.

The out-of-bounds learn weak spot (CWE-125) permits attackers to entry reminiscence areas past meant boundaries. Efficiently exploiting this vulnerability requires membership in particular person teams with elevated permissions.

Making this a focused menace, primarily affecting organizations with strict entry controls and privileged-user monitoring protocols.

Safety researchers from Kunlun Lab deserve credit score for responsibly disclosing this vulnerability to Microsoft by coordinated disclosure channels.

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to characteristic your tales.

Cyber Security News Tags:Attackers, Data, Defender, Disclose, Firewall, Sensitive, Service, Vulnerability, Windows

Post navigation

Previous Post: Adobe Acrobat Reader Vulnerabilities let Attackers Execute Arbitrary Code and Bypass Security
Next Post: Active Attacks Exploit Gladinet’s Hard-Coded Keys for Unauthorized Access and Code Execution

Related Posts

Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms Unauthorized Access to Anthropic’s AI Cyber Tool Raises Security Alarms Cyber Security News
Citrix Warns Authentication Failures Following The Update of NetScaler to Fix Auth Vulnerability Citrix Warns Authentication Failures Following The Update of NetScaler to Fix Auth Vulnerability Cyber Security News
SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE SolarWinds Web Help Desk Vulnerability Enables Unauthenticated RCE Cyber Security News
Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations Threat Actors Deploying CoinMiner Malware via USB Drives Infecting Workstations Cyber Security News
SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month SafePay Ransomware Claiming Attacks Over 73 Victim Organizations in a Single Month Cyber Security News
Threat Actors Weaponizing Facebook Ads to Deliver Malware and Stealing Wallet Passwords Threat Actors Weaponizing Facebook Ads to Deliver Malware and Stealing Wallet Passwords Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • VMware Fusion Vulnerability Receives Critical Update
  • Critical Vulnerability in MongoDB Risks Data Exposure
  • Windows Zero-Day Exploits: YellowKey and GreenPlasma Revealed
  • Fragnesia Linux Kernel Vulnerability Allows Root Access
  • NGINX Vulnerability Allows Remote Code Execution

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark