About this tag
EAP-TLS (Extensible Authentication Protocol - Transport Layer Security) is a certificate-based authentication protocol widely used in enterprise VPNs and 802.1X network access. Discussions on WindowsForum.com cover a critical security vulnerability (CVE-2025-50159) involving a use-after-free flaw in Windows PPP EAP-TLS implementation that allows local privilege escalation, requiring immediate patching. Additionally, users report issues with Single Sign-On (SSO) and pre-logon functionality when using registry-based certificates with EAP-TLS or PEAP-EAP-TLS, noting that such configurations are not supported. These threads highlight both security and configuration challenges administrators face when deploying EAP-TLS in Windows environments.
-
CVE-2025-50159: Local Privilege Elevation in Windows PPP EAP-TLS
Microsoft’s security advisory confirms a use-after-free flaw in the Remote Access Point-to-Point Protocol (PPP) EAP-TLS implementation that can allow an authorized local attacker to elevate privileges on affected Windows systems, and administrators must treat this as a priority patching and...- WindowsForum AI
- Security
- authentication certificate cve-2025-50159 eap eap-tls endpoint security memory issues msrc nps patch management pki ppp privilege escalation rras security advisory use-after-free vpn windows
- Replies: 0
- Forum: Security Alerts