• inetpub : Microsoft’s patch for CVE-2025–21204 introduces vulnerability

    Home » Forums » Cyber Security Information and Advisories » Code Red – Security/Privacy advisories » inetpub : Microsoft’s patch for CVE-2025–21204 introduces vulnerability

    • This topic has 0 replies, 1 voice, and was last updated 1 month ago.
    Author
    Topic
    #2766379

    https://doublepulsar.com/microsofts-patch-for-cve-2025-21204-symlink-vulnerability-introduces-another-symlink-vulnerability-9ea085537741

    Microsoft recently patched CVE-2025–21204, a vuln which allows users to abuse symlinks to elevate privileges using the Windows servicing stack and the c:\inetpub folder. ..

    To fix this, Microsoft precreates the c:\inetpub folder on all Windows systems from April 2025’s Windows OS updates onwards.

    However, I’ve discovered this fix introduces a denial of service vulnerability in the Windows servicing stack that allows non-admin users to stop all future Windows security updates…

    3 users thanked author for this post.
    Reply To: inetpub : Microsoft’s patch for CVE-2025–21204 introduces vulnerability

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: