CVE-2025-47956 describes a spoofing vulnerability within the Microsoft Windows Security App, allowing an authorized local attacker to manipulate file names or paths. This medium-severity flaw (CVSS 5.5) has a low attack complexity and requires local user privileges, potentially leading to high confidentiality impacts but no integrity or availability compromise. While there is no public exploit code or active exploitation reported, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1000.27840.0.1000CPE matchmatch criteria | cpe:2.3:a:microsoft:windows_security_app:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.