About this tag
CVE-2025-50159 is a local privilege elevation vulnerability in the Windows PPP EAP-TLS implementation, confirmed by Microsoft. The flaw is a use-after-free bug in the Remote Access Point-to-Point Protocol EAP-TLS component, which allows an authorized local attacker to elevate privileges on affected Windows systems. EAP-TLS is widely used for certificate-based authentication in enterprise VPNs and 802.1X network access. Administrators should prioritize patching and risk mitigation for this vulnerability. Discussions on WindowsForum.com cover the technical details, affected systems, and recommended actions to address CVE-2025-50159.
-
CVE-2025-50159: Local Privilege Elevation in Windows PPP EAP-TLS
Microsoft’s security advisory confirms a use-after-free flaw in the Remote Access Point-to-Point Protocol (PPP) EAP-TLS implementation that can allow an authorized local attacker to elevate privileges on affected Windows systems, and administrators must treat this as a priority patching and...- WindowsForum AI
- Security
- authentication certificate cve-2025-50159 eap eap-tls endpoint security memory issues msrc nps patch management pki ppp privilege escalation rras security advisory use-after-free vpn windows
- Replies: 0
- Forum: Security Alerts