CVE-2025-47987 is an elevation-of-privilege vulnerability in the Windows Credential Security Support Provider Protocol (CredSSP). The flaw is described as a heap-based buffer overflow in the CredSSP component and has also been associated with integer overflow or wraparound conditions during processing of authentication-related data. Available reporting indicates the issue can be triggered when CredSSP handles crafted oversized authentication tokens or related input without sufficient bounds validation, leading to heap corruption. Successful exploitation allows a locally authorized attacker to execute code in a more privileged context and escalate from a low-privilege account to SYSTEM on the affected host.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a small Windows local privilege-escalation PoC centered on Exploit.c, plus two Markdown documents (README.md and Cpp.md) that describe CVE-2025-47987 and usage. The actual exploit logic is entirely in Exploit.c. It is a standalone C program, not part of a common exploit framework. Exploit.c includes Windows SSPI/CredSSP headers and links against secur32.lib. It defines a packed KERB_CERT_LOGON_HEADER-like structure and a helper, BuildExploitPayload(), which computes aligned offsets for username, password, domain, and certificate/CSP data, allocates a buffer with VirtualAlloc, populates the header fields, and copies attacker-controlled data into the final blob. In main(), the program dynamically resolves WinExec from kernel32.dll, allocates a massive buffer of size 0xFFFFFF00, fills that buffer with the WinExec pointer as a spray/grooming pattern, embeds it into the crafted auth structure, and calls AcquireCredentialsHandleW with package name TSSSP and the malicious authData pointer. The exploit capability is local memory-corruption triggering against Windows CredSSP/TSSSP processing, with the stated goal of elevating privileges to SYSTEM. However, the code as provided is closer to a trigger PoC than a complete end-to-end privilege-escalation exploit: it checks for SEC_E_INTERNAL_ERROR and prints that as evidence of possible corruption, but does not include a full post-exploitation chain, token theft, shell spawn, or reliable control-transfer logic beyond spraying a function pointer. Still, it is more than a detector because it actively constructs malformed input and attempts to trigger the vulnerable code path. Fingerprintable targets/endpoints are mostly local API and module references rather than network infrastructure: kernel32.dll, WinExec, the TSSSP package string, and AcquireCredentialsHandleW. No hardcoded remote IPs, domains, or C2 endpoints are present in the exploit code. The Markdown files contain external reference URLs to MSRC and NVD, but these are documentation artifacts rather than operational exploit communications.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-47987, targeting the Windows authentication subsystem via the TSSSP security package. The main file, 'CVE-2025-47987.c', is a C program that constructs a specially crafted authentication buffer, including a large fake CSP (Cryptographic Service Provider) data structure. This buffer is then passed to the Windows API function AcquireCredentialsHandleW with the TSSSP package, aiming to trigger a crash in the authentication process. The exploit is local and requires execution on a Windows system. The repository also includes a README with a link to a technical analysis and a standard MIT license. No network endpoints or remote attack vectors are present; the exploit is purely local and targets the Windows authentication mechanism.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
23 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Credential Security Support Provider Protocol (CredSSP) elevation of privilege vulnerability identified as more likely to be exploited.
An elevation of privilege vulnerability in CredSSP, rated as more likely to be exploited.
A heap-based buffer overflow in Windows CredSSP that can allow an authenticated local attacker to escalate privileges to SYSTEM.
A local elevation of privilege vulnerability in Windows Credential Security Support Provider Protocol (CredSSP), caused by a heap-based buffer overflow and integer overflow/wraparound conditions, that could allow an authorized attacker to gain SYSTEM privileges.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.