Improper Access Control in Windows Storage VSP Driver by Microsoft
CVE-2025-59517
7.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-59517?
The Windows Storage VSP Driver contains an access control vulnerability that allows an authenticated attacker to elevate privileges locally. This flaw poses a risk as it can potentially enable unauthorized actions on affected systems. It emphasizes the need for users to maintain updated software and apply security patches promptly to mitigate risks associated with local privilege escalation.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8688
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8146
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6691