CVE-2025-2230

CVSS 3.1 Score 7.7 of 10 (high)

Details

Published Mar 13, 2025
CWE ID 287

Summary

CVE-2025-2230 is a vulnerability affecting the Windows login flow, where an attacker can exploit an AuthContext token for replay attacks and bypass authentication. This issue allows unauthorized access to systems and services protected by the vulnerable login process. The token, which is intended to be a one-time use credential, can be intercepted and reused to gain access to user accounts, potentially leading to privileged escalation. Microsoft has released a patch to address this vulnerability, and it is recommended that users install the update as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Philips Intellispace Cardiovascular

Affected Vendors

  • Philips