CVE-2025-59199

7.8

Microsoft · Windows

Improper access control in the Microsoft Windows Software Protection Platform (SPP) allows a locally authenticated attacker to elevate their privileges on the system.

Executive summary

A vulnerability in the Microsoft Windows Software Protection Platform allows a local attacker to achieve privilege escalation, posing a significant risk to system integrity.

Vulnerability

This flaw is an improper access control issue (CWE-284) within the Software Protection Platform (SPP). It requires the attacker to already have low-level local access to the system to successfully execute the privilege escalation.

Business impact

The ability for a standard user to elevate privileges to a higher level of authority significantly undermines the security posture of the affected operating systems. Successful exploitation could lead to full system compromise, unauthorized data access, and the potential for persistent malware installation. Given the CVSS score of 7.8, this vulnerability is categorized as High severity and requires prompt attention to prevent unauthorized administrative control.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide to bring the system build numbers to or above the fixed versions.

Proactive Monitoring: Review system access logs for unusual account activity or unexpected privilege changes that may indicate an attempt to exploit local access control flaws.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced and limit the ability of standard users to execute unauthorized binaries or scripts that could leverage this vulnerability.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations should prioritize patching affected Windows environments to eliminate this privilege escalation vector. While the vulnerability requires local access, the potential for total system compromise necessitates that administrators treat this as a high-priority update to protect sensitive assets and maintain system stability.

More Microsoft CVEs

Sources