Cyber Posture

CVE-2025-48822

High

Published: 08 July 2025

Published
08 July 2025
Modified
15 July 2025
KEV Added
Patch
CVSS Score 8.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
EPSS Score 0.0051 66.5th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-48822 is a high-severity Out-of-bounds Read (CWE-125) vulnerability in Microsoft Windows 10 1607. Its CVSS base score is 8.6 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 33.5% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-2 (Flaw Remediation) and SI-10 (Information Input Validation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Directly remediates the out-of-bounds read vulnerability in Windows Hyper-V through timely application of vendor-provided patches to prevent local code execution.

prevent

Implements memory protection mechanisms that mitigate arbitrary code execution resulting from exploitation of the out-of-bounds read in Hyper-V.

prevent

Validates inputs to Hyper-V components to prevent malformed data that could trigger the out-of-bounds read vulnerability exploited by tricking a user.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

OOB read in Hyper-V directly enables local exploitation for arbitrary code execution with scope change and high impacts on confidentiality/integrity/availability, mapping to privilege escalation via vulnerability exploitation.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.

Deeper analysisAI

CVE-2025-48822 is an out-of-bounds read vulnerability (CWE-125) affecting Windows Hyper-V. Published on 2025-07-08, it carries a CVSS v3.1 base score of 8.6 (AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H), indicating high severity due to its potential for significant impact.

A local unauthorized attacker can exploit this vulnerability with low attack complexity by tricking a user into performing a specific action. Successful exploitation allows the attacker to execute arbitrary code, achieving high impacts on confidentiality, integrity, and availability, with a scope change to other privileged components.

Microsoft's update guide provides details on mitigation and patches for CVE-2025-48822 at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48822.

Details

CWE(s)

Affected Products

microsoft
windows 10 1607
≤ 10.0.14393.8246
microsoft
windows 10 1809
≤ 10.0.17763.7558
microsoft
windows 10 21h2
≤ 10.0.19044.6093
microsoft
windows 10 22h2
≤ 10.0.19045.6093
microsoft
windows 11 22h2
≤ 10.0.22621.5624
microsoft
windows 11 23h2
≤ 10.0.22631.5624
microsoft
windows 11 24h2
≤ 10.0.26100.4652
microsoft
windows server 2016
≤ 10.0.14393.8246
microsoft
windows server 2019
≤ 10.0.17763.7558
microsoft
windows server 2022
≤ 10.0.20348.3932
+2 more product configuration(s) — see NVD for full list

CVEs Like This One

CVE-2025-49687Same product: Microsoft Windows 10 1607
CVE-2025-24050Same product: Microsoft Windows 10 1607
CVE-2026-25174Same product: Microsoft Windows 10 1607
CVE-2026-23672Same product: Microsoft Windows 10 1607
CVE-2026-23673Same product: Microsoft Windows 10 1607
CVE-2026-25175Same product: Microsoft Windows 10 1607
CVE-2025-24048Same product: Microsoft Windows 10 1607
CVE-2026-26153Same product: Microsoft Windows 10 1809
CVE-2025-24059Same product: Microsoft Windows 10 1607
CVE-2026-26156Same product: Microsoft Windows 10 1607

References