CVE-2025-29800 is an improper privilege management vulnerability in Microsoft AutoUpdate (MAU) that allows an authorized local attacker to elevate privileges. With a CVSS score of 7.8 (HIGH), this vulnerability has low attack complexity and could lead to high impacts on confidentiality, integrity, and availability. While it is not currently listed on CISA's KEV catalog and no public exploit code exists, it has garnered significant community discussion and media coverage, including mention in a BleepingComputer article about Microsoft's April 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.78CPE matchmatch criteria | cpe:2.3:a:microsoft:autoupdate:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.