CVE-2025-59517: Windows Storage VSP Driver Elevation of Privilege Vulnerability
Improper access control in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
Other sources
Windows Storage VSP Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6691Patch KB5071546 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4529Fixed in 10.0.20348.4467Patch KB5071413 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8146Patch KB5071544 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7462Fixed in 10.0.26100.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8688Patch KB5071543 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7462Fixed in 10.0.26200.7392Patch KB5072014 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6345Patch KB5071417 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2025Patch KB5071542
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59517?
CVE-2025-59517 is classified as a high-severity vulnerability due to its potential to allow unauthorized privilege escalation.
How do I fix CVE-2025-59517?
To fix CVE-2025-59517, apply the appropriate security patches provided by Microsoft for your affected Windows version.
What does CVE-2025-59517 affect?
CVE-2025-59517 affects various Microsoft Windows operating systems, including Windows 10, Windows 11, and Windows Server editions.
Is CVE-2025-59517 being exploited in the wild?
There are currently no public reports confirming that CVE-2025-59517 is actively exploited in the wild.
Can CVE-2025-59517 be remotely exploited?
CVE-2025-59517 requires local access to exploit, making it less likely to be exploited remotely.