CVE-2025-29969PoC(microsoft / windows_10_1507)

MEDIUMCVSS 7.5 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch microsoft windows_10_1507 systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Time-of-check time-of-use (toctou) race condition in Windows Fundamentals allows an authorized attacker to execute code over a network.

4.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • windows_10_1507
  • windows_10_1607
  • windows_10_1809
  • windows_10_21h2

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 11 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 5 signals
  • PoC mentioned or linked in 7 signals
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 12 signals
  • Disclosure: 3 classified signals
  • Peaked 9d ago at 3 mentions (2026-02-20); latest day: 1
  • 17 total mentions across 11 days

Affected systems

Vendors
Products
windows_10_1507windows_10_1607windows_10_1809windows_10_21h2windows_10_22h2windows_11_22h2windows_11_23h2windows_11_24h2windows_server_2008windows_server_2012

2 versions affected across 15 products

Deep dive

Activity timeline17 mentions / 11d
01223Mentions · 2026-02-19: 2Mentions · 2026-02-20: 3Mentions · 2026-02-24: 1Mentions · 2026-02-27: 1Mentions · 2026-03-01: 1Mentions · 2026-03-15: 2Mentions · 2026-03-16: 2Mentions · 2026-03-17: 2Mentions · 2026-03-22: 1Mentions · 2026-07-21: 1Mentions · 2026-07-30: 1PoC Mentioned / Linked · 2026-02-19: 2PoC Mentioned / Linked · 2026-03-15: 2PoC Mentioned / Linked · 2026-03-16: 2PoC Mentioned / Linked · 2026-03-17: 1Exploit Tool / Code · 2026-02-19: 2Exploit Tool / Code · 2026-03-15: 1Exploit Tool / Code · 2026-03-16: 1Exploit Tool / Code · 2026-03-17: 1Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-01: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-07-21: 1Patch / Workaround · 2026-07-30: 1Technical Details · 2026-02-19: 2Technical Details · 2026-02-20: 1Technical Details · 2026-02-24: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-01: 1Technical Details · 2026-03-15: 2Technical Details · 2026-03-16: 1Technical Details · 2026-03-22: 1Technical Details · 2026-07-21: 1Technical Details · 2026-07-30: 102-1902-2002-2402-2703-0103-1503-1603-1703-2207-2107-30
Signal classification5 categories
PoC
635.3%
Patch
423.5%
Disclosure
317.6%
Exploit
211.8%
General
211.8%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-192
Exploit1PoC1
2026-02-203
Disclosure2General1
2026-02-241
Disclosure1
2026-02-271
Patch1
2026-03-011
Patch1
2026-03-152
PoC2
2026-03-162
PoC2
2026-03-172
Exploit1PoC1
2026-03-221
General1
2026-07-211
Patch1
2026-07-301
Patch1
Full discourse17 posts
  • Gray Hats@the_yellow_fall
    PoC

    Researcher releases PoC exploit code for EventLogin, a TOCTOU flaw in Windows MS-EVEN RPC allowing remote file writes. Patch now. https://securityonline.info/poc-disclosed-eventlogin-windows-ms-even-rpc-cve-2025-29969/ https://t.co/xbpnKuBqA5

    Post summary

    A researcher shared proof‑of‑concept exploit code for CVE‑2025‑29969—a TOCTOU flaw in Windows MS‑EVE RPC that permits remote file writes—and a patch is now available.

    275129817918.1K
    10.7K followersView on X
  • Or Yair@oryair1999
    Exploit

    New blog & exploit about CVE-2025-29969 - RCE by Yarin Aharoni @safebreach Labs. Findings allow: ---- * Checking arbitrary paths existence (unfixed!). * Writing files remotely (RCE). ---- On ALL Windows & Windows Server computers in the domain! Repo - https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969

    Post summary

    The post announces CVE-2025-29969, a Windows RCE vulnerability, with a PoC and functional exploit code on GitHub, detailing path checks and remote file writes, but does not report active exploitation.

    130088435.3K
    865 followersView on X
  • moton@moton
    PoC

    PoC Exploit Disclosed: Researcher Unveils Windows MS-EVEN RPC Vulnerability - https://securityonline.info/poc-disclosed-eventlogin-windows-ms-even-rpc-cve-2025-29969/

    Post summary

    The post announces that a PoC exploit for CVE‑2025‑29969, a Windows MS‑EVEN RPC vulnerability, has been disclosed.

    015085404.8K
    658 followersView on X
  • Mr. OS@ksg93rd
    PoC

    EventLogin — CVE-2025-29969 A flaw in the MS-EVEN protocol. Low-privileged users can write arbitrary files to a remote machine, effectively bypassing the need for an administrator account for remote file writes 🔗 Source: https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969 🔗 Research: https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/ #ad #windows #eventlog #rpc

    Post summary

    SafeBreach Labs disclosed CVE‑2025‑29969, a flaw in the MS‑EVEN protocol that allows low‑privileged users to remotely write arbitrary files, and provided a proof‑of‑concept repository on GitHub.

    04028101.3K
    3.2K followersView on X
  • Pixis@HackAndDo
    Patch

    When I saw the CVE-2025-29969 fix (by @safebreach), I knew there was more to it. It's not as critical as it seems, but it was fun trying to find a way to still exploit this EventLog RPC endpoint

    Post summary

    The post notes a published fix for CVE-2025-29969 by @safebreach, indicates the issue is less critical, and mentions ongoing attempts to exploit the EventLog RPC endpoint.

    0601954.2K
    8.2K followersView on X
  • Login Sécurité@LoginSecurite
    Patch

    Microsoft : "on a bien patché la CVE-2025-29969" @HackAndDo : "hold my beer" Microsoft : "😮" Pour les détails, c'est sur le blog de Login Sécurité : https://login-securite.com/blog/cve-2026-50502-rce-via-le-service-windows-event-log-elfrbackupelfw

    Post summary

    Microsoft confirms it has patched CVE-2025-29969; a blog provides technical details on CVE-2026-50502, an RCE vulnerability via the Windows Event Log.

    0411173.4K
    556 followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    EventLog-in: Propagating With Weak Credentials Using the Eventlog Service in Microsoft Windows (CVE-2025-29969) https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/

    Post summary

    The article announces CVE-2025-29969, describing how weak credentials can be exploited via the Windows Eventlog service, but it does not provide PoC, exploit code, patch information, or evidence of active exploitation.

    00093861
    150.9K followersView on X
  • Blue Team News@blueteamsec1
    General

    EventLog-in: Propagating With Weak Credentials Using the Eventlog Service in Microsoft Windows (CVE-2025-29969) http://dlvr.it/TRdh5p #cyber #threathunting #infosec

    Post summary

    The post references CVE‑2025‑29969, describing a weakness involving weak credentials via the Windows Eventlog service, but offers no PoC, exploit code, patch information, or evidence of active exploitation.

    04052877
    55.2K followersView on X
  • /r/netsec@_r_netsec
    General

    Discovery & Analysis of CVE-2025-29969 https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/

    Post summary

    The post announces the discovery and analysis of CVE-2025-29969 but does not provide additional details on PoC, exploit availability, active exploitation, patch, or technical specifics.

    02071555
    32.6K followersView on X
  • ᅟ𝖎𝖑𝖑𝖜𝖎𝖑𝖑@xillwillx
    PoC

    although patched May last year , you might get lucky https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969

    Post summary

    A tweet points to a GitHub repo that appears to host a proof‑of‑concept for CVE‑2025‑29969, noting the issue was patched in May; no evidence of active exploitation or detailed vulnerability data is provided.

    00011466
    3.0K followersView on X
  • Scurippio@scurippio
    Exploit

    @al3x_n3ff You can also now weaponize the cve-2025-29969 ;)), good stuff as always! Love it!

    Post summary

    The message indicates that CVE-2025-29969 can be weaponized, implying the availability of an exploit, but it does not provide any explicit exploit code, tool, patch information, or detailed technical details about the vulnerability.

    00010156
    36 followersView on X
  • bigmacd@bigmacd16684
    Disclosure

    CVE-2025-29969 is a remote code execution vulnerability in MS-EVEN RPC protocol on Windows 11 and Windows Server 2025, letting low-privileged users write files remotely. #cybersecurity #vulnerability

    Post summary

    The post announces CVE‑2025‑29969 as a remote code execution flaw in the MS‑EVEN RPC protocol affecting Windows 11 and Server 2025, enabling low‑privileged users to write files remotely.

    1000046
    1 followersView on X
  • Karma-X@Karma_X_Inc
    PoC

    PoC Exploit Disclosed: Researcher Unveils Windows MS-EVEN RPC Vulnerability https://securityonline.info/poc-disclosed-eventlogin-windows-ms-even-rpc-cve-2025-29969/

    Post summary

    A researcher disclosed a proof‑of‑concept exploit for the Windows MS‑EVEN RPC vulnerability (CVE‑2025‑29969), but no details on active exploitation, patches, or technical specifics are provided.

    00000146
    70 followersView on X
  • cybrmakr@cybrmaker
    Patch

    SafeBreach Labs found CVE-2025-29969. This high-severity heap-based buffer overflow allows unauthenticated RCE in Trend Micro Apex One and Worry-Free Business Security products. Patches have been released. PS: Visit olivermaicher[.]eu

    Post summary

    SafeBreach Labs identified a high‑severity heap‑based buffer overflow (CVE‑2025‑29969) in Trend Micro Apex One and Worry‑Free Business Security, enabling unauthenticated RCE; patches have been released.

    00000178
  • cybrmakr@cybrmaker
    Patch

    SafeBreach discovered CVE-2025-29969 in Microsoft Azure Site Recovery agent. This allows Local Privilege Escalation by loading a malicious DLL with SYSTEM privileges. Microsoft patched the flaw in June 2024. Update your ASR agents.

    Post summary

    SafeBreach identified a local privilege escalation vulnerability (CVE-2025-29969) in Azure Site Recovery agents; Microsoft has patched it, and users should update their agents promptly.

    0000040
  • Security Harvester@secharvesterx
    Disclosure

    Discovery & Analysis of CVE-2025-29969 https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/ https://t.co/hNltLVY1wW

    Post summary

    Safebreach Labs has announced the discovery and analysis of CVE-2025-29969 through a blog post, without providing further technical details or exploit information.

    0000058
    382 followersView on X
  • 💻🥷 WarthogTK 🩺 🇺🇦🇪🇺✈️@warthogtk
    PoC

    EventLog-in: Propagating With Weak Credentials Using the Eventlog Service in Microsoft Windows (CVE-2025-29969) https://www.safebreach.com/blog/safebreach_labs_discovers_cve-2025-29969/ https://github.com/SafeBreach-Labs/EventLogin-CVE-2025-29969

    Post summary

    Safebreach Labs has disclosed CVE‑2025‑29969, a weak‑credential flaw in Windows Eventlog, and provided a Proof of Concept on GitHub, with no indication of active exploits or available patches.

    0000062
    1.7K followersView on X
CPE platform detail27 entries

27 of 27 entries

PartVendorProductVersionTarget SWTarget HW
OSmicrosoftwindows_10_1507--x64
OSmicrosoftwindows_10_1507--x86
OSmicrosoftwindows_10_1607--x64
OSmicrosoftwindows_10_1607--x86
OSmicrosoftwindows_10_1809--x64
OSmicrosoftwindows_10_1809--x86
OSmicrosoftwindows_10_21h2--arm64
OSmicrosoftwindows_10_21h2--x64
OSmicrosoftwindows_10_21h2--x86
OSmicrosoftwindows_10_22h2--arm64
OSmicrosoftwindows_10_22h2--x64
OSmicrosoftwindows_10_22h2--x86
OSmicrosoftwindows_11_22h2--arm64
OSmicrosoftwindows_11_22h2--x64
OSmicrosoftwindows_11_23h2--arm64
OSmicrosoftwindows_11_23h2--x64
OSmicrosoftwindows_11_24h2--arm64
OSmicrosoftwindows_11_24h2--x64
OSmicrosoftwindows_server_2008---
OSmicrosoftwindows_server_2008r2-x64
OSmicrosoftwindows_server_2012---
OSmicrosoftwindows_server_2012r2--
OSmicrosoftwindows_server_2016---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
OSmicrosoftwindows_server_2022_23h2---
OSmicrosoftwindows_server_2025---

Explore more