logo

Microsoft Brokering File System Vulnerability Let Attackers Escalate Privileges

ID: 61e28173-6d74-5f74-b99b-7d3863f97852

STIX ID: report--61e28173-6d74-5f74-b99b-7d3863f97852

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2025-12-22

Date Updated: 2026-04-21

Author: Abinaya

...
...

Microsoft patched a high-severity use-after-free vulnerability (CVE-2025-29970, CVSS 8.8) in the Brokering File System (bfs.sys) used by AppContainer/AppSilo sandboxes; the flaw arises from improper deallocation of a DirectoryBlockList head and can be abused by local attackers to escalate privileges. The report (discovered by HT3Labs) details exploitation requirements — impersonating AppSilo tokens, creating policy entries, and forcing rapid add-remove IOCTL cycles — notes medium-integrity processes can access the BFS device, and urges organizations to apply the January 2025 patch and monitor sandboxed environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.