Sep 2025: Windows Defender Firewall Service Elevation of Privilege Vulnerability
CVE-2025-54915 Published on September 9, 2025
Windows Defender Firewall Service Elevation of Privilege Vulnerability
Access of resource using incompatible type ('type confusion') in Windows Defender Firewall Service allows an authorized attacker to elevate privileges locally.
Weakness Type
What is an Object Type Confusion Vulnerability?
The program allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.
CVE-2025-54915 has been classified to as an Object Type Confusion vulnerability or weakness.
Products Associated with CVE-2025-54915
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 1507:- Version 10.0.10240.0 and below 10.0.10240.21128 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.19044.0 and below 10.0.19044.6332 is affected.
- Version 10.0.19045.0 and below 10.0.19045.6332 is affected.
- Version 10.0.22621.0 and below 10.0.22621.5909 is affected.
- Version 10.0.22631.0 and below 10.0.22631.5909 is affected.
- Version 10.0.22631.0 and below 10.0.22631.5909 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27929 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27929 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23529 is affected.
- Version 6.0.6003.0 and below 6.0.6003.23529 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25675 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25675 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22774 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22774 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.14393.0 and below 10.0.14393.8422 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.17763.0 and below 10.0.17763.7792 is affected.
- Version 10.0.20348.0 and below 10.0.20348.4171 is affected.
- Version 10.0.25398.0 and below 10.0.25398.1849 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6584 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.