HIGH 7.8 Microsoft
CVE-2025-48637
In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Microsoft Security Update 2025-Dec: In multiple functions of mem_protect.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
Affected Products
- azl3 hyperv-daemons 6.6.119.3-1 on Azure Linux 3.0
- azl3 hyperv-daemons 6.6.121.1-1 on Azure Linux 3.0
- cbl2 hyperv-daemons 5.15.186.1-1 on CBL Mariner 2.0
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-48637
- https://nvd.nist.gov/vuln/detail/CVE-2025-48637
This high severity vulnerability with a CVSS score of 7.8 was published on 2025-12-09 via Microsoft. Affected: azl3 hyperv-daemons 6.6.119.3-1 on Azure Linux 3.0, azl3 hyperv-daemons 6.6.121.1-1 on Azure Linux 3.0, cbl2 hyperv-daemons 5.15.186.1-1 on CBL Mariner 2.0.
vulnfeed aggregates 9044 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.