Elevation of Privilege Vulnerability in Windows Kernel by Microsoft
CVE-2025-59194
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 14 October 2025
Badges
What is CVE-2025-59194?
An elevation of privilege vulnerability exists in the Windows Kernel due to the use of uninitialized resources. An attacker who successfully exploits this vulnerability can gain elevated privileges, allowing them to execute arbitrary code with elevated rights on a local system. This could lead to significant security breaches, emphasizing the importance of applying security updates to mitigate risks.
Affected Version(s)
Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.6060
Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22631.6060
Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.6060
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved