Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-47987 — Technical analysis and documentation of CVE-2025-47987, a Windows CredSSP heap-based buffer overflow vulnerability enabling local privilege escalation to SYSTEM. | Kitploit
Tools/GitHubGitHub/kaleth4/cve-2025-47987
Privilege EscalationVulnerability AnalysisExploitationPapers & ResearchLearning & EducationBinary Exploitation
GitHubkaleth4/cve-2025-47987

CVE-2025-47987

Technical analysis and documentation of CVE-2025-47987, a Windows CredSSP heap-based buffer overflow vulnerability enabling local privilege escalation to SYSTEM.

View Repository
24 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-47987: Windows CredSSP Elevation of Privilege

📌 This repository contains documentation and analysis resources about the vulnerability CVE-2025-47987, a heap-based buffer overflow flaw affecting the Windows Credential Security Support Provider (CredSSP) protocol.


📝 Description

The vulnerability allows an authenticated local attacker to elevate their privileges on the system. The flaw originates from improper memory management when processing specific CredSSP protocol packets, which can lead to:

  • A heap-based buffer overflow
  • Or an integer overflow (Integer Overflow)

Identifier: CVE-2025-47987
Vulnerability Type: Elevation of Privilege (EoP)
Weaknesses (CWE):

  • CWE-122: Heap-based Buffer Overflow
  • CWE-190: Integer Overflow or Wraparound
    Severity (CVSS 3.1): 7.8 HIGH
    Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

💻 Affected Systems

The vulnerability affects a wide range of Microsoft operating systems, including:

  • Windows 10 (versions 1507 through 22H2)
  • Windows 11 (versions 22H2, 23H2, and 24H2)
  • Windows Server: 2008, 2012, 2016, 2019, 2022, 2025

✅ Critical Note: An update to a build version later than those indicated in the Microsoft Security Update Guide is required to mitigate the risk.

🔍 See the full list of affected CPEs below.


🛠️ Mitigation and Solution

✅ Main Solution:

Apply the official security patches distributed by Microsoft through Windows Update.

  • Official Update: Microsoft Security Update Guide — CVE-2025-47987
  • Post-patch Verification: Run winver or systeminfo and confirm that the build version exceeds the thresholds listed above.

⚠️ There are no effective workarounds (such as disabling CredSSP), as it would affect critical functionalities like Remote Desktop, WinRM, and PowerShell Remoting.


🔍 Technical Analysis

The overflow occurs within the Credential Security Support Provider (CredSSP), specifically during the processing of NTLM/Kerberos authentication structures in the context of credential delegation (credential delegation).

Key Points:

  • Required Access: Local + authenticated (not remote).
  • User Interaction: UI:N → No interaction required.
  • Impact: Total compromise of Confidentiality, Integrity, and Availability (C:H/I:H/A:H).
  • Typical scenario: An attacker with standard user privileges sends a malicious request to a service using CredSSP (e.g., termsrv, lsass), corrupting the heap and achieving code execution with SYSTEM privileges.

⚠️ Disclaimer

This content is provided for informational and cybersecurity research purposes only.

❌ Using this information to compromise systems without explicit authorization is illegal and violates international laws (e.g., CFAA, Organic Law on Data Protection, GDPR, etc.).

✅ Legitimate uses include: authorized audits, ethical penetration testing, defense development, IDS/EDR detection, and supervised academic training.

Official Sources:

  • NIST National Vulnerability Database — CVE-2025-47987
  • Microsoft Security Response Center (MSRC)

📚 Known Affected Software Configurations (CPE 2.2)

📣 Missing a CPE? Report your finding to [email protected] (authorized researchers only)!


📎 References

  • Microsoft Security Advisory — CVE-2025-47987 (Vendor Advisory)
  • NVD — CVE-2025-47987 Detail
  • CWE-122: Heap-based Buffer Overflow
  • CWE-190: Integer Overflow or Wraparound

🔐 Last updated: 2025-04-05 — Based on public data from MSRC and NVD.
🛠️ This README.md file is licensed under CC BY-NC-SA 4.0 for educational and non-commercial research use.

Download Tool
SystemMaximum Vulnerable VersionExample Minimum Safe Build
Windows 11 24H210.0.26100.4652 (excl.)10.0.26100.4653+
Windows Server 202210.0.20348.3932 (excl.)10.0.20348.3933+
Windows 10 22H210.0.19045.6093 (excl.)10.0.19045.6094+
CPE IdentifierStatusNotes
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*VulnerableUp to (excl.) 10.0.10240.21073
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*VulnerableUp to (excl.) 10.0.14393.8246
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*VulnerableUp to (excl.) 10.0.17763.7558
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.19044.6093
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.19045.6093
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.22621.5624
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.22631.5624
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.26100.4652
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*VulnerableNo specified build limit
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*VulnerableNo specified build limit
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.14393.8246
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.17763.7558
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.20348.3932
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.25398.1732
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*VulnerableUp to (excl.) 10.0.26100.4652