You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
credssp vulnerability
About this tag
The credssp vulnerability tag covers discussions about security flaws in the Credential Security Support Provider protocol (CredSSP) in Microsoft Windows. A key topic is CVE-2025-47987, a critical heap-based buffer overflow that allows an authenticated attacker to elevate privileges locally. CredSSP is an authentication provider used by Remote Desktop Protocol (RDP) and Windows Remote Management. Tagged content includes security alerts, mitigation strategies, and technical analysis of the vulnerability. Users share information about patching, workarounds, and the impact on enterprise environments. The tag is relevant for IT administrators, security professionals, and Windows users concerned with system integrity and credential security.
A critical security vulnerability, identified as CVE-2025-47987, has been discovered in the Credential Security Support Provider protocol (CredSSP) within Microsoft Windows. This flaw is a heap-based buffer overflow that allows an authenticated attacker to elevate privileges locally, posing...