Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data
A critical vulnerability has been identified in the Windows Defender Firewall Service, enabling authorized attackers to access sensitive heap memory on affected systems. This vulnerability is documented as CVE-2025-62468 and was released on December 9,…
A critical vulnerability has been identified in the Windows Defender Firewall Service, enabling authorized attackers to access sensitive heap memory on affected systems. This vulnerability is documented as CVE-2025-62468 and was released on December 9, 2025, with an Important severity rating.
The flaw is due to an out-of-bounds read condition in the Windows Defender Firewall Service component. Microsoft’s security advisory indicates that an attacker with high-level privileges can exploit this vulnerability to read parts of heap memory without user interaction, impacting data confidentiality but not system integrity or availability. The CVSS v3.1 base score for this vulnerability is 4.4.
Local attack vector Low attack complexity High privileges required No user interaction needed
Microsoft has assessed the likelihood of exploitation as unlikely, with no public exploit code or active exploitation reported at the time of disclosure. Security updates addressing CVE-2025-62468 are available across multiple Windows platforms .
Product KB Article Build Numbers
Windows Server 2025 KB5072033, KB5072014 10.0.26100.7462 / 10.0.26100.7392
Windows 11 Version 24H2 (x64) KB5072033, KB5072014 10.0.26100.7462 / 10.0.26100.7392
This vulnerability is documented as CVE-2025-62468 and was released on December 9, 2025, with an Important severity rating.
Windows 11 Version 24H2 (ARM64) KB5072033, KB5072014 10.0.26100.7462 / 10.0.26100.7392
Windows Server 2022 23H2 (Server Core) KB5071542 10.0.25398.2025
Windows 11 Version 23H2 (x64) KB5071417 10.0.22631.6345
Windows 11 Version 23H2 (ARM64) KB5071417 10.0.22631.6345
Windows 11 Version 25H2 (x64) KB5072033, KB5072014 10.0.26200.7462 / 10.0.26200.7392
Windows 11 Version 25H2 (ARM64) KB5072033, KB5072014 10.0.26200.7462 / 10.0.26200.7392
Patches are available for various versions of Windows Server and Windows 11, and can be obtained through Microsoft Update or the Microsoft Update Catalog. The updates include standard security patches and security hotpatch updates, allowing flexible deployment strategies. Administrators are advised to apply these updates promptly to mitigate risks.
The vulnerability requires high-level privilege escalation, limiting its immediate threat scope. It highlights the importance of restricting administrative access and monitoring privileged user activities. The out-of-bounds read weakness (CWE-125) allows access to memory beyond intended boundaries, necessitating membership in specific user groups with elevated permissions.
This issue primarily affects organizations with strict access controls and privileged-user monitoring protocols . Security researchers from Kunlun Lab are credited for responsibly disclosing this vulnerability to Microsoft through coordinated disclosure channels.
Based on reporting by Cyber Security News.
