Advertisement

Microsoft patched a vulnerability by making the Inetpub folder, but created a new one

This month, Microsoft fixed a vulnerability in Windows, identified as CVE-2025–21204 , that allowed attackers to perform and/or manipulate file management operations on a victim’s computer with the privileges of the NT AUTHORITY\SYSTEM account. To mitigate this issue, the April 2025 update introduced a new folder: %systemdrive%\inetpub , even for devices not running Internet Information Services (IIS).

However, this fix inadvertently introduced a new vulnerability that could prevent the installation of future Windows security updates, as highlighted by noted security researcher Kevin Beaumont.

The issue occurs because any user can create a symbolic link that redirects the system path C:\inetpub to another object, such as the Notepad application. Therefore, attempts to install the April 2025 update and likely future updates result in errors or rollbacks of changes made.

Inetpub Vulnerability

For example, the following command creates a symbolic link (in the screenshot above):

mklink /j c:\inetpub c:\windows\system32\notepad.exe

Malicious people can use this method to prevent the installation of future security updates that could fix vulnerabilities used to attack systems. However, running such a command requires administrator rights and physical access to the computer.

Beaumont reported the issue to the Microsoft Security Research Center (MSRC) about two weeks ago, but has not yet received a response.

Thanks to thecommunity.

Support us

Winaero greatly relies on your support. You can help the site keep bringing you interesting and useful content and software by using these options:

If you like this article, please share it using the buttons below. It won't take a lot from you, but it will help us grow. Thanks for your support!

Author: Sergey Tkachenko

Sergey Tkachenko is a software developer who started Winaero back in 2011. On this blog, Sergey is writing about everything connected to Microsoft, Windows and popular software. Follow him on Telegram, Twitter, and YouTube.

One thought on “Microsoft patched a vulnerability by making the Inetpub folder, but created a new one”

Leave a Reply

Your email address will not be published.

css.php
Using Telegram? Subscribe to the blog channel!
Hello. Add your message here.