CVE-2025-48819CWE-591

Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability

High · published July 8, 2025

CVSS v3.1
7.1
EPSS
0%
Percentile
25.9
In the wild
Unconfirmed
What it is

Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.

The record
Technical detail
CVSS v3.1
7.1 · HIGH
Vector
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00332 · 25.9th percentile
Weakness
CWE-591 · Sensitive Data Storage in Improperly Locked Memory
Published
2025-07-08T16:57Z
EPSS history
Timeline
  • 08 JUL 16:57Z
    Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
    cvelistv5