Microsoft Brokering File System Vulnerability Let Attackers Escalate Privileges
ID: 61e28173-6d74-5f74-b99b-7d3863f97852
STIX ID: report--61e28173-6d74-5f74-b99b-7d3863f97852
Feed Name: cybersecurityNews.com
Microsoft patched a high-severity use-after-free vulnerability (CVE-2025-29970, CVSS 8.8) in the Brokering File System (bfs.sys) used by AppContainer/AppSilo sandboxes; the flaw arises from improper deallocation of a DirectoryBlockList head and can be abused by local attackers to escalate privileges. The report (discovered by HT3Labs) details exploitation requirements — impersonating AppSilo tokens, creating policy entries, and forcing rapid add-remove IOCTL cycles — notes medium-integrity processes can access the BFS device, and urges organizations to apply the January 2025 patch and monitor sandboxed environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
