---
cve: "CVE-2025-32701"
severity: "HIGH"
cvss: 7.8
epss: "1.4%"
vendor: "Microsoft"
kev: true
exploited: true
published: "2025-05-13 17:16:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T14:16:25+02:00"
---

# CVE-2025-32701

> 7.8 HIGH · ⚠️ CISA KEV (515 Tage) · 🔓 Exploited

## Beschreibung

Use after free in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA KEV seit: **13.05.2025**
- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **active**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Microsoft Windows Server: Mehrere Schwachstellen ermöglichen Privilegieneskalation](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2025-1050) — _BSI-Einstufung: hoch_
  Ein entfernter, anonymer Angreifer, oder lokaler Angreifer, oder ein Angreifer aus einem angrenzenden Netzwerk kann mehrere Schwachstellen in Microsoft Windows Server, Microsoft Windows Server 2012, Microsoft Windows Server 2012 R2, Microsoft Windows 10, Microsoft Windows Server 2016, Microsoft Windows Server 2019, Microsoft Windows, Microsoft Windows Server 2022 und Microsoft Windows 11 ausnutzen, um einen Denial-of-Service auszulösen, Informationen offenzulegen, beliebigen Programmcode auszuführen oder seine Privilegien zu erweitern.

## Referenzen

- <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-32701>
- <https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-32701>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2025-32701/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
