CVE-2025-60709

Description

Out-of-bounds read in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.049

Associated Vulnerability

VulnerabilityOS Platform
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x86-based Systems (KB5068864)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows Server 2016 for x64-based Systems (KB5068864)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 1607 for x64-based Systems (KB5068864)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x64-based Systems (KB5068791)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 1809 for x86-based Systems (KB5068791)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows Server 2019 for x64-based Systems (KB5068791)Windows
2025-11 Cumulative Update for Windows 10 Version 22H2 for x86-based Systems (KB5068781)Windows
2025-11 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5068781)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 21H2 for x64-based Systems (KB5068781)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 10 Version 21H2 for x86-based Systems (KB5068781)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11 Version 23H2 for arm64-based Systems (KB5068865)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11 Version 23H2 for x64-based Systems (KB5068865)Windows
2025-11 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5068907)Windows
2025-11 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB5068905)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Microsoft server operating system version 23H2 for x64-based Systems (KB5068779)Windows
2025-11 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB5068909)Windows
2025-11 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB5068909)Windows
2025-11 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB5068908)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11, version 25H2 for x64-based Systems (KB5068861) (26200.7171) (CVE-2025-62215)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Microsoft server operating system version 24H2 for x64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11 Version 24H2 for x64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11, version 25H2 for arm64-based Systems (KB5068861) (26200.7171) (CVE-2025-62215)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Windows 11 Version 24H2 for arm64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)Windows
Windows Smart Card Reader Elevation of Privilege Vulnerability for Microsoft server operating system version 21H2 for x64-based Systems (KB5068787) (CVE-2025-62215)Windows
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability for Windows Server 2008 for x64-based Systems (KB5068906) (ESU)Windows
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability for Windows Server 2008 for x86-based Systems (KB5068906) (ESU)Windows
Windows Bluetooth RFCOM Protocol Driver Information Disclosure Vulnerability for Windows Server 2008 R2 for x64-based Systems (KB5068904) (ESU)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-428922025-11 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB5068864)
PATCH-428932025-11 Cumulative Update for Windows Server 2016 for x64-based Systems (KB5068864)
PATCH-428942025-11 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB5068864)
PATCH-428952025-11 Cumulative Update for Windows 10 Version 1809 for x64-based Systems (KB5068791) (CVE-2025-62215)
PATCH-428962025-11 Cumulative Update for Windows 10 Version 1809 for x86-based Systems (KB5068791) (CVE-2025-62215)
PATCH-428972025-11 Cumulative Update for Windows Server 2019 for x64-based Systems (KB5068791) (CVE-2025-62215)
PATCH-428982025-11 Cumulative Update for Windows 10 Version 22H2 for x86-based Systems (KB5068781) (ESU) (CVE-2025-62215)
PATCH-428992025-11 Cumulative Update for Windows 10 Version 22H2 for x64-based Systems (KB5068781) (ESU) (CVE-2025-62215)
PATCH-429002025-11 Cumulative Update for Windows 10 Version 21H2 for x64-based Systems (KB5068781) (CVE-2025-62215)
PATCH-429012025-11 Cumulative Update for Windows 10 Version 21H2 for x86-based Systems (KB5068781) (CVE-2025-62215)
PATCH-429022025-11 Cumulative Update for Windows 11 Version 23H2 for arm64-based Systems (KB5068865) (CVE-2025-62215)
PATCH-429032025-11 Cumulative Update for Windows 11 Version 23H2 for x64-based Systems (KB5068865) (CVE-2025-62215)
PATCH-428762025-11 Security Monthly Quality Rollup for Windows Server 2012 for x64-based Systems (KB5068907) (ESU)
PATCH-428752025-11 Security Monthly Quality Rollup for Windows Server 2012 R2 for x64-based Systems (KB5068905) (ESU)
PATCH-428862025-11 Cumulative Update for Microsoft server operating system version 23H2 for x64-based Systems (KB5068779) (CVE-2025-62215)
PATCH-428702025-11 Security Only Quality Update for Windows Server 2008 for x64-based Systems (KB5068909) (ESU)
PATCH-428712025-11 Security Only Quality Update for Windows Server 2008 for x86-based Systems (KB5068909) (ESU)
PATCH-428692025-11 Security Only Quality Update for Windows Server 2008 R2 for x64-based Systems (KB5068908) (ESU)
PATCH-428872025-11 Cumulative Update for Windows 11, version 25H2 for x64-based Systems (KB5068861) (26200.7171) (CVE-2025-62215)
PATCH-428882025-11 Cumulative Update for Microsoft server operating system version 24H2 for x64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)
PATCH-428892025-11 Cumulative Update for Windows 11 Version 24H2 for x64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)
PATCH-428902025-11 Cumulative Update for Windows 11, version 25H2 for arm64-based Systems (KB5068861) (26200.7171) (CVE-2025-62215)
PATCH-428912025-11 Cumulative Update for Windows 11 Version 24H2 for arm64-based Systems (KB5068861) (26100.7171) (CVE-2025-62215)
PATCH-428852025-11 Cumulative Update for Microsoft server operating system version 21H2 for x64-based Systems (KB5068787) (CVE-2025-62215)
PATCH-428732025-11 Security Monthly Quality Rollup for Windows Server 2008 for x64-based Systems (KB5068906) (ESU)
PATCH-428742025-11 Security Monthly Quality Rollup for Windows Server 2008 for x86-based Systems (KB5068906) (ESU)
PATCH-428722025-11 Security Monthly Quality Rollup for Windows Server 2008 R2 for x64-based Systems (KB5068904) (ESU)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234