CVE-2025-55697 is a high-severity heap-based buffer overflow vulnerability in Azure Local, affecting Microsoft Windows Server 2022 23H2 and Windows Server 2025. An authorized local attacker can exploit this flaw to achieve significant privilege escalation, leading to high impact on confidentiality, integrity, and availability. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered notable community discussion and media coverage, indicating awareness within the security landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.25398.1913CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.6899CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.