CVE-2025-47968 is a high-severity vulnerability in Microsoft AutoUpdate (MAU) that allows an authenticated local attacker to achieve privilege escalation due to improper input validation. With a CVSS score of 7.8, successful exploitation could lead to high impact on confidentiality, integrity, and availability of the affected system. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's June 2025 Patch Tuesday. This suggests it is a notable flaw, though it is not currently listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.79CPE matchmatch criteria | cpe:2.3:a:microsoft:autoupdate:*:*:*:*:*:macos:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.