Microsoft’s patch for CVE-2025–21204 symlink vulnerability introduces another symlink vulnerability
ID: 99717f2e-7222-5904-a720-8c8bda8a8d89
STIX ID: report--99717f2e-7222-5904-a720-8c8bda8a8d89
Feed Name: DoublePulsar
Threat Score
Microsoft’s fix for CVE-2025-21204 (precreating c:\inetpub) can be abused by a non-admin user creating a junction (e.g., mklink /j c:\inetpub c:\windows\system32\notepad.exe) that causes the Windows servicing stack to fail and roll back updates, effectively blocking future security updates; the researcher disclosed the issue to MSRC and recommends EDR detection for junctions targeting \inetpub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
