CVE-2025-59282: Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Other sources
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59282?
CVE-2025-59282 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-59282?
To mitigate CVE-2025-59282, apply the security patches provided by Microsoft immediately.
What systems are affected by CVE-2025-59282?
CVE-2025-59282 affects several versions of Windows including Windows 10, Windows 11, and Windows Server editions.
What type of vulnerability is CVE-2025-59282?
CVE-2025-59282 is a race condition vulnerability that can lead to unauthorized local code execution.
Who is at risk from CVE-2025-59282?
Unauthorized attackers can exploit CVE-2025-59282 to execute malicious code on vulnerable systems.