CVE-2025-59196: Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SSDP Service allows an authorized attacker to elevate privileges locally.
Other sources
Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59196?
CVE-2025-59196 is classified as a privilege escalation vulnerability.
How do I fix CVE-2025-59196?
To fix CVE-2025-59196, apply the latest patches provided by Microsoft for your affected Windows version.
Which versions of Windows are affected by CVE-2025-59196?
CVE-2025-59196 affects multiple Windows Server versions including 2008, 2012, 2016, and 2022, as well as various Windows 10 and 11 versions.
What type of vulnerability is CVE-2025-59196?
CVE-2025-59196 is a race condition vulnerability in the Windows SSDP Service that can allow attackers to elevate privileges.
Can CVE-2025-59196 be exploited remotely?
CVE-2025-59196 requires local access for exploitation, as it involves privilege escalation on affected Windows systems.