CVE-2025-59192
7.8Microsoft · Windows
A buffer over-read vulnerability in the Storport.sys driver allows a locally authenticated attacker to elevate their privileges on the host system.
Executive summary
A local privilege escalation vulnerability in the Windows Storport.sys driver, rated as High severity, poses a significant risk to system integrity and security.
Vulnerability
This is a buffer over-read flaw (CWE-126) within the Storport.sys driver. An attacker who has already obtained local authenticated access to the system can exploit this vulnerability to escalate their privileges to a higher level.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its potential to grant an attacker full control over a local system once they have gained initial access. Successful exploitation could lead to unauthorized data access, the installation of malicious software, and the compromise of critical system functions, resulting in significant operational downtime and security breaches.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to address the Storport.sys driver vulnerability.
Proactive Monitoring: Monitor system logs for unusual behavior or unauthorized attempts to access sensitive kernel-level functions or processes.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced, limiting the number of users who possess local access rights to critical systems, which effectively narrows the attack surface for this local exploit.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of this privilege escalation flaw, organizations should prioritize the deployment of the vendor-supplied patches across all affected Windows environments. Administrators must ensure that the specific build versions listed are updated to the corrected releases to mitigate the risk of local exploitation.
More Microsoft CVEs
Sources
- Storport.sys Driver Elevation of Privilege Vulnerability Vendor advisory