Advisory Details

August 14th, 2025

Microsoft Windows Subsystem for Linux WslCoreVm::Initialize Incorrect Privilege Management Information Disclosure Vulnerability

ZDI-25-844
ZDI-CAN-27541

CVE ID CVE-2025-53788
CVSS SCORE 4.7, AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
AFFECTED VENDORS Microsoft
AFFECTED PRODUCTS Windows
VULNERABILITY DETAILS

This vulnerability allows local attackers to read arbitrary files on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within WslCoreVm::Initialize method. The issue results from incorrect management of privileges. An attacker can leverage this vulnerability to read files in the context of SYSTEM.

ADDITIONAL DETAILS Microsoft has issued an update to correct this vulnerability. More details can be found at:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53788
DISCLOSURE TIMELINE
  • 2025-07-09 - Vulnerability reported to vendor
  • 2025-08-14 - Coordinated public release of advisory
  • 2025-08-14 - Advisory Updated
CREDIT William Gamazo Sanchez and Nitesh Surana of Trend Research
BACK TO ADVISORIES