SafeBreach Labs disclosed CVE-2025-29969, a Windows vulnerability in the MS-EVEN (EventLog) RPC protocol that allowed a low-privileged domain user to achieve remote code execution across an Active Directory network. The attack targeted the default-enabled EventLog service over the named pipe \PIPE\eventlog, where researchers found primitives for remote file and directory existence checks based on differing error codes, as well as a way to write files remotely by abusing the ElfrOpenBELW and ElfrBackupELFW functions.
The exploit chain relied on a time-of-check/time-of-use (TOCTOU) flaw: a benign .evtx header was validated when a remote SMB-hosted file was opened, then the file contents were swapped before backup so arbitrary content could be written to a chosen path on the target system. SafeBreach demonstrated code execution by placing a batch file in a user Startup folder and by writing a malicious DLL for a per-user OneDrive DLL hijack. Microsoft was notified in February 2025 and patched the RCE path in May 2025, although the researchers said some reconnaissance-style behaviors, including remote existence checks and related information-gathering capabilities, remain unpatched.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
Microsoft patched CVE-2025-29969 in May 2025. According to SafeBreach, the patch addressed the TOCTOU-based remote code execution technique, while some recon-style behaviors remained unpatched.
SafeBreach reported CVE-2025-29969 to Microsoft after discovering an Active Directory domain-network RCE chain involving the Windows EventLog RPC interface. The issue allowed low-privileged remote interaction that could be abused for remote file checks and arbitrary file writes leading to code execution.
SafeBreach publicly disclosed technical details of CVE-2025-29969, describing exploitation of the MS-EVEN EventLog protocol over the \PIPE\eventlog named pipe. The write-up included the remote file-write primitive, the TOCTOU exploitation method, and demonstrated code execution scenarios involving a Startup folder batch file and a OneDrive DLL hijack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.