CVE-2025-29811

Improper input validation in Windows Mobile Broadband allows an authorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*

History

10 Jul 2025, 14:51

Type Values Removed Values Added
First Time Microsoft
Microsoft windows 11 23h2
Microsoft windows 11 24h2
Microsoft windows Server 2022 23h2
Microsoft windows Server 2025
Microsoft windows 11 22h2
CPE cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29811 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29811 - Vendor Advisory

09 Apr 2025, 20:03

Type Values Removed Values Added
Summary
  • (es) La validación de entrada incorrecta en Windows Mobile Broadband permite que un atacante autorizado eleve privilegios localmente.

08 Apr 2025, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-08 18:16

Updated : 2025-07-10 14:51


NVD link : CVE-2025-29811

Mitre link : CVE-2025-29811

CVE.ORG link : CVE-2025-29811


JSON object : View

Products Affected

microsoft

  • windows_11_23h2
  • windows_11_22h2
  • windows_11_24h2
  • windows_server_2025
  • windows_server_2022_23h2
CWE
CWE-20

Improper Input Validation

CWE-122

Heap-based Buffer Overflow

CWE-125

Out-of-bounds Read