CVE-2025-59194
Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.
- Affected products
- Windows, Windows Kernel
- Microsoft Windows 11 22h2
- < 10.0.22621.6060
- Microsoft Windows 11 23h2
- ≤ 10.0.22631.6060
- Microsoft Windows 11 24h2
- < 10.0.26100.6899
- Microsoft Windows 11 25h2
- < 10.0.26200.6899
- Microsoft Windows Server 2022 23h2
- < 10.0.25398.1913
- Microsoft Windows Server 2025
- ≤ 10.0.26100.6899
- CVSS 3.1
- 7.0 HIGH
- EPSS
- 2.5% (83th percentile)
- Weakness
- CWE-908
- NVD status
- Analyzed
- Published
- 2025-10-14
CVE-2025-59194 at NVD
1 known exploit for CVE-2025-59194
Proof-of-concept code and exploit modules indexed by Sploitus