logo

Microsoft’s patch for CVE-2025–21204 symlink vulnerability introduces another symlink vulnerability

ID: 99717f2e-7222-5904-a720-8c8bda8a8d89

STIX ID: report--99717f2e-7222-5904-a720-8c8bda8a8d89

Feed Name: DoublePulsar

Threat Score
65/100

Date Published: 2025-04-22

Date Updated: 2026-04-19

Author: Kevin Beaumont

...
...

Microsoft’s fix for CVE-2025-21204 (precreating c:\inetpub) can be abused by a non-admin user creating a junction (e.g., mklink /j c:\inetpub c:\windows\system32\notepad.exe) that causes the Windows servicing stack to fail and roll back updates, effectively blocking future security updates; the researcher disclosed the issue to MSRC and recommends EDR detection for junctions targeting \inetpub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.