CVE-2025-59206: Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Published Oct 14, 2025
·Updated
Windows Resilient File System (ReFS) Deduplication Service Elevation of Privilege Vulnerability
Affected Software
9 affected componentsFixes available
Microsoft Windows 11=24H2
Microsoft Windows 11=25H2
Microsoft Windows 11=25H2
Microsoft Windows Server 2025
Microsoft Windows 11=24H2
Microsoft Windows Server 2025
Microsoft Windows 11 24h2<10.0.26100.6899
Microsoft Windows 11 25h2<10.0.26200.6899
Microsoft Windows Server 2025<=10.0.26100.6899
Event History
Oct 14, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59206?
CVE-2025-59206 is classified as a medium-severity elevation of privilege vulnerability.
2
How do I fix CVE-2025-59206?
To fix CVE-2025-59206, apply the latest security update from Microsoft for your affected Windows version.
3
What products are affected by CVE-2025-59206?
CVE-2025-59206 affects specific versions of Windows 11 and Windows Server 2025.
4
Can CVE-2025-59206 be exploited remotely?
CVE-2025-59206 requires local access to exploit, making remote exploitation unlikely.
5
What impact can CVE-2025-59206 have on my system?
Exploitation of CVE-2025-59206 could allow an attacker to gain elevated privileges on a vulnerable system.