CVE-2025-48799 is an elevation-of-privilege vulnerability in the Windows Update Service caused by improper link resolution before file access, also described as link following. The flaw stems from inadequate validation of symbolic link targets during privileged file operations, creating a local Time-of-Check to Time-of-Use condition in which attacker-controlled links can redirect the service’s file access to unintended locations. Because the Windows Update Service operates with SYSTEM privileges, an authorized local attacker with low privileges can abuse the vulnerable link handling to cause privileged create, modify, or delete operations on protected files and thereby escalate to SYSTEM-level access.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept exploit for CVE-2025-48799, a remote code execution vulnerability in Apache Tomcat 9.0.48. The exploit is implemented in C (exploit_tomcat_48799.c) and demonstrates how to trigger an integer overflow in the HTTP header parser by sending an oversized 'X-Forwarded' header. The code constructs a malicious HTTP request, injects shellcode (a placeholder for spawning a shell), and sends it to a specified target IP and port using libcurl. The README.md offers a detailed explanation of the vulnerability, exploitation technique, and ethical usage guidelines. The repository is structured simply, with the main exploit code, a license, and documentation. The exploit is a POC and requires the attacker to specify the target's IP and port. If successful, it may result in a shell on the target system. No hardcoded IPs or domains are present; the target is specified at runtime.
This repository is a Proof-of-Concept (PoC) exploit for CVE-2025-48799, a local privilege escalation vulnerability in the Windows Update service (wuauserv) on Windows 10 and 11 systems with multiple hard drives. The exploit abuses the ability to change the default save location for new applications to a secondary drive. By manipulating symbolic links and exploiting a race condition during application installation, the exploit causes the Windows Update service to perform arbitrary folder deletion as SYSTEM without proper symlink validation. The main exploit logic is implemented in C++ across several files, with 'main.cpp' serving as the entry point. Supporting files handle oplock management, resource extraction, and low-level file/registry operations. The exploit requires user interaction to trigger the vulnerable operation and proceeds in two stages: preparation and privilege escalation. Notable fingerprintable endpoints include the 'C:\Config.Msi' directory, the Windows Temp directory, a specific DLL path, and a relevant registry key. The exploit does not provide a weaponized payload but demonstrates the vulnerability and the steps required to achieve SYSTEM privileges.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-48799, a local privilege escalation vulnerability in the Windows Update service on Windows 10 and Windows 11 systems with multiple hard drives. The exploit abuses the ability to change the default save location for new applications to a secondary drive. By manipulating symbolic links and leveraging the Windows Update service's improper handling of folder deletions, the attacker can cause the service to delete arbitrary folders as SYSTEM, leading to privilege escalation. The repository is structured as a Visual Studio C++ project with the following key files: - `main.cpp`: The main entry point, orchestrating the exploit stages. - `FileOrFolderDelete.cpp`: Implements the core logic for exploiting the arbitrary file/folder delete vulnerability. - `FileOplock.cpp`/`FileOplock.h`: Implements opportunistic locking to synchronize exploit steps. - `def.h`: Contains definitions, global variables, and function prototypes. - Resource files (`resource.h`, `resource.rc`) and project files for building the executable. The exploit operates in two stages: first, it prepares the environment and triggers the vulnerable folder deletion via the Windows Update service; second, it resumes after the deletion to complete the privilege escalation. The exploit interacts with several fingerprintable endpoints, including the `C:\Config.Msi` folder, the Windows Temp directory, and relevant registry keys. The code is a functional PoC and does not include a weaponized or highly automated payload, but demonstrates the full exploit chain for local SYSTEM privilege escalation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Windows Update Service elevation of privilege vulnerability identified as more likely to be exploited.
A Windows Update Service elevation of privilege vulnerability caused by improper symbolic link resolution / TOCTOU behavior that can allow authenticated local attackers to gain SYSTEM-level access.
A local elevation of privilege vulnerability in Windows Update Service caused by improper link resolution before file access ('link following'). Successful exploitation could allow an authorized attacker to create, modify, or delete files as NT AUTHORITY\SYSTEM.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.