CVE-2025-48819CWE-591
Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
High · published July 8, 2025
What it is
Sensitive data storage in improperly locked memory in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges over an adjacent network.
The record
Technical detail
- CVSS v3.1
- 7.1 · HIGH
- Vector
- CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- CVSS v4.0
- Not supplied
- EPSS
- 0.00332 · 25.9th percentile
- Weakness
- CWE-591 · Sensitive Data Storage in Improperly Locked Memory
- Published
- 2025-07-08T16:57Z
EPSS history
Timeline