CVE-2025-59201

7.8

Microsoft · Windows

Improper access control in the Windows Network Connection Status Indicator (NCSI) allows a local, authenticated attacker to achieve privilege escalation.

Executive summary

A local privilege escalation vulnerability in the Microsoft Windows Network Connection Status Indicator allows authenticated users to gain elevated system permissions.

Vulnerability

This vulnerability involves improper access control within the Network Connection Status Indicator (NCSI) component. An attacker with low-level local access can exploit this flaw to escalate privileges to a higher level of authority.

Business impact

Successful exploitation allows an attacker to bypass standard operating system security controls, potentially gaining full control over the local system. With a CVSS score of 7.8, this vulnerability represents a significant risk to organizational integrity, as it facilitates the transition from a restricted user account to a privileged administrator or system context.

Remediation

Immediate Action: Update all affected Windows systems to the specified patched versions or newer via the official Microsoft Update Catalog.

Proactive Monitoring: Monitor endpoint logs for unusual process execution or unauthorized attempts to access system-level services associated with network configuration.

Compensating Controls: Strictly enforce the principle of least privilege by ensuring standard users do not possess unnecessary administrative rights, which limits the initial access an attacker requires to trigger the exploit.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for complete system compromise, administrators should prioritize the deployment of the relevant security updates across the enterprise. Failure to patch these systems allows attackers who have gained initial local access to significantly expand their capabilities, making this update a critical component of standard patch management cycles.

More Microsoft CVEs

Sources