Elevation of Privilege Vulnerability in Windows Kernel by Microsoft
CVE-2025-59194

7HIGH

What is CVE-2025-59194?

An elevation of privilege vulnerability exists in the Windows Kernel due to the use of uninitialized resources. An attacker who successfully exploits this vulnerability can gain elevated privileges, allowing them to execute arbitrary code with elevated rights on a local system. This could lead to significant security breaches, emphasizing the importance of applying security updates to mitigate risks.

Affected Version(s)

Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.6060

Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22631.6060

Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.6060

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59194 : Elevation of Privilege Vulnerability in Windows Kernel by Microsoft