CVE-2025-59195: Windows Graphics Component Denial of Service Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.
Other sources
Microsoft Graphics Component Denial of Service Vulnerability
— Microsoft
Windows Graphics Component Denial of Service Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
Exploitation requires local access and authorization on the target system. The vector indicates low privileges are required, but the attack complexity is high and no user interaction is required.
Which systems should be assessed for exposure?
Assess Microsoft Windows 11, Windows 10, Windows Server 2025, Windows Server 2022, and Windows Server 2019, including the listed Windows 10 1809 and 21H2 and Windows Server 2022 23H2 Edition entries. The provided data does not identify specific affected build or update levels.
How can I determine whether an asset may be affected?
Compare the asset's operating system and edition with the listed software. Because no fixed versions or patch identifiers are provided, this data alone cannot confirm whether a particular build is remediated.