Microsoft disclosed CVE-2025-49738, an Important elevation-of-privilege vulnerability in Microsoft PC Manager that could allow a locally authorized attacker with low privileges to escalate to SYSTEM without user interaction. The issue stems from improper link resolution before file access, tracked as CWE-59, and carries a CVSS 3.1 score of 7.8.
Microsoft said an official fix is available and assessed exploitation as less likely. The company also stated the flaw had not been publicly disclosed and was not known to be exploited at the time of publication. The vulnerability was credited to security researcher Simon (@sim0nsecurity) through coordinated vulnerability disclosure.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft disclosed CVE-2025-49738, an Important elevation of privilege vulnerability in Microsoft PC Manager caused by improper link resolution before file access. The advisory states an official fix is available and that the issue was neither publicly disclosed nor exploited at the time of publication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
msrc.microsoft.com
Open sourcemsrc.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.