Privilege Escalation
The latest Privilege Escalation coverage — news, analysis, and updates from the WindowsNews.AI desk.
CVE-2025-59194: Windows Kernel Privilege Escalation Vulnerability Patched
Microsoft has confirmed and patched a critical Windows kernel elevation-of-privilege vulnerability tracked as CVE-2025-59194, describing it as a use of uninitialized resource in kernel code that...
Microsoft Patches Critical CVE-2025-58734 Inbox COM Memory Vulnerability
Microsoft has addressed a significant security vulnerability in Windows systems with the release of a patch for CVE-2025-58734, a critical memory flaw affecting Inbox COM Objects that could enable...
CVE-2025-59191: Critical Windows CDPSvc Privilege Escalation Vulnerability
A critical security vulnerability in Windows' Connected Devices Platform Service (CDPSvc) has been identified, posing significant risks to millions of Windows systems worldwide. Designated as...
CVE-2025-59189: Critical Windows BFS Vulnerability Enables Local Privilege Escalation
Microsoft has disclosed a significant security vulnerability in its Brokering File System (BFS) component that could allow attackers to gain elevated privileges on affected Windows systems....
CVE-2025-59187 Windows Kernel Vulnerability: Critical Privilege Escalation Patch
Microsoft has issued an urgent security update addressing CVE-2025-59187, a critical Windows Kernel elevation-of-privilege vulnerability that could allow attackers to gain SYSTEM-level access on...
CVE-2025-58736: Critical Windows COM Memory Vulnerability Patched in October 2025 Update
Microsoft has addressed a critical security vulnerability in Windows COM objects that could allow attackers to escalate privileges on affected systems. CVE-2025-58736, patched in the October 2025...
CVE-2025-58726: Critical Windows SMB Server Privilege Escalation Vulnerability Analysis
Microsoft has disclosed a significant security vulnerability in the Windows Server Message Block (SMB) protocol that could allow authenticated attackers to escalate privileges over network...
Patches released for CVE-2025-58714 AFD driver flaw granting attackers SYSTEM access
Microsoft has confirmed a serious elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) that could allow attackers to gain SYSTEM-level privileges on...
CVE-2025-58714: Critical WinSock AFD Vulnerability Enables Local Privilege Escalation
Microsoft has issued an urgent security advisory for CVE-2025-58714, a critical elevation-of-privilege vulnerability in the Windows Ancillary Function Driver for WinSock that enables attackers to...
Windows CDPSvc UAF Vulnerability CVE-2025-58727: Critical Patch Required
A critical use-after-free vulnerability in Windows' Connected Devices Platform Service (CDPSvc) has been identified as CVE-2025-58727, posing significant elevation-of-privilege risks for...
CVE-2025-58725: Critical Windows COM+ EoP Vulnerability Requires Immediate Patching
Microsoft has disclosed a critical elevation-of-privilege vulnerability in the Windows COM+ Event System, designated CVE-2025-58725, that could allow attackers to gain SYSTEM privileges on affected...
Microsoft Patches Azure Arc Agent Bug That Gives Attackers Full Control of Servers
Microsoft has patched a high-severity vulnerability in its Azure Connected Machine agent that could allow a limited user to gain complete control over a server—and potentially the cloud resources...