Headline
CVE-2025-49760: Windows Storage Spoofing Vulnerability
According to the CVSS metric, user interaction is required (UI:R) and privileges required is Low (PR:L). What does that mean for this vulnerability?
An authorized attacker with low privileges creates a scheduled task that is set to run when a user logs on and spoofs interfaces that belong to many services so the victim can connect to the attacker’s server instead of the original.
Microsoft Security Response Center: Latest News
CVE-2025-49729: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability