Microsoft Discloses Windows File Explorer and NTFS Elevation of Privilege Flaws
Microsoft published security advisories for two Windows elevation of privilege vulnerabilities affecting core operating system components: Windows File Explorer (CVE-2025-62565) and Windows NTFS (CVE-2025-55335). The flaws were listed in the Microsoft Security Update Guide as separate issues impacting widely deployed Windows functionality tied to file browsing and the NTFS file system.
The advisories provide limited public technical detail, but both issues could allow an attacker with existing access to a vulnerable system to gain higher privileges. Because the affected components are integral to Windows operations, organizations should review Microsoft’s update guidance for the relevant CVEs, prioritize patch deployment across supported Windows assets, and monitor for follow-on research or exploit activity that could increase operational risk.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
2 events from the most recent confirmed update back to the earliest known activity.
Microsoft publishes advisory for CVE-2025-62565
Microsoft added CVE-2025-62565, a Windows File Explorer Elevation of Privilege Vulnerability, to its Security Update Guide.
Microsoft publishes advisory for CVE-2025-55335
Microsoft added CVE-2025-55335, a Windows NTFS Elevation of Privilege Vulnerability, to its Security Update Guide.
Sources
2 references tracked. Mallory keeps watching after this page renders.
CVE-2025-62565 - Security Update Guide - Microsoft - Windows File Explorer Elevation of Privilege Vulnerability
msrc.microsoft.com
Open sourceCVE-2025-55335 - Security Update Guide - Microsoft - Windows NTFS Elevation of Privilege Vulnerability
msrc.microsoft.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


