CVE-2025-47993 is an improper access control vulnerability in Microsoft PC Manager affecting Windows 11 24H2, Windows Server 2022 23H2, and Windows Server 2025, allowing a local, authorized attacker to achieve privilege escalation. Rated 7.8 HIGH, this vulnerability requires low attack complexity and user privileges, but can lead to high impact on confidentiality, integrity, and availability. While not currently in the KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness despite no active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.26100.4652CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:* | ||
< 10.0.25398.1732CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.4652CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.