Microsoft Windows VBS Enclave Privilege Escalation Vulnerability

Vulnerability

A vulnerability exists in Windows Virtualization-Based Security (VBS) Enclave due to improper handling of untrusted inputs in security decisions. This flaw allows an authorized attacker to locally elevate privileges. Successful exploitation could enable the attacker to access data from the targeted enclave or execute code within it.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain elevated rights within the affected system.

Remediation

Users can apply the security update available through the Microsoft Update Catalog. For guidance on blocking the rollback of VBS-related security updates, refer to the updated policy available on the Microsoft Support website.

Added: Oct 14, 2025, 5:21 PM
Updated: Oct 14, 2025, 10:03 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.