CVE-2025-59192

7.8

Microsoft · Windows

A buffer over-read vulnerability in the Storport.sys driver allows a locally authenticated attacker to elevate their privileges on the host system.

Executive summary

A local privilege escalation vulnerability in the Windows Storport.sys driver, rated as High severity, poses a significant risk to system integrity and security.

Vulnerability

This is a buffer over-read flaw (CWE-126) within the Storport.sys driver. An attacker who has already obtained local authenticated access to the system can exploit this vulnerability to escalate their privileges to a higher level.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its potential to grant an attacker full control over a local system once they have gained initial access. Successful exploitation could lead to unauthorized data access, the installation of malicious software, and the compromise of critical system functions, resulting in significant operational downtime and security breaches.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the Storport.sys driver vulnerability.

Proactive Monitoring: Monitor system logs for unusual behavior or unauthorized attempts to access sensitive kernel-level functions or processes.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced, limiting the number of users who possess local access rights to critical systems, which effectively narrows the attack surface for this local exploit.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of this privilege escalation flaw, organizations should prioritize the deployment of the vendor-supplied patches across all affected Windows environments. Administrators must ensure that the specific build versions listed are updated to the corrected releases to mitigate the risk of local exploitation.

More Microsoft CVEs

Sources