CVE-2025-59516: Windows Storage VSP Driver Elevation of Privilege Vulnerability
Missing authentication for critical function in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Other sources
Windows Storage VSP Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6345Patch KB5071417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2025Patch KB5071542 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8146Patch KB5071544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4529Fixed in 10.0.20348.4467Patch KB5071413
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59516?
CVE-2025-59516 is classified as an elevation of privilege vulnerability in the Windows Storage VSP Driver.
How do I fix CVE-2025-59516?
To address CVE-2025-59516, you should apply the security updates provided by Microsoft for your affected Windows product.
Who is affected by CVE-2025-59516?
CVE-2025-59516 affects multiple versions of Microsoft Windows, including Windows 10, Windows 11, and Windows Server variants.
Can CVE-2025-59516 be exploited remotely?
CVE-2025-59516 requires local access for an attacker to exploit the vulnerability.
What type of vulnerability is CVE-2025-59516?
CVE-2025-59516 is an elevation of privilege vulnerability, allowing a user to gain higher access levels than intended.