Missing authorization in Windows StateRepository API allows an authorized attacker to perform tampering locally.
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49723 | vendor advisory |