
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59517 is an improper access control vulnerability in the Windows Storage VSP Driver that allows an authorized local attacker to elevate privileges. Disclosed on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday, it affects a broad range of Windows operating systems including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2), and Windows Server 2016, 2019, 2022, and 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC).
The vulnerability is rooted in improper access control (CWE-284) within the Windows Storage VSP (Virtual Storage Provider) Driver. An attacker with low-privilege local access can exploit this flaw without requiring user interaction, leveraging insufficient access control enforcement in the driver to escalate privileges to SYSTEM level. The attack vector is local, with low attack complexity and no privilege or interaction requirements beyond an authenticated user account (Microsoft MSRC, Qualys Blog).
Successful exploitation allows a low-privileged local attacker to gain SYSTEM-level access, resulting in full compromise of confidentiality, integrity, and availability on the affected host. An attacker could install malware, modify critical system files, access sensitive data, disable security controls, and establish persistent access. The broad scope of affected Windows versions — spanning consumer and server editions — significantly widens the potential attack surface (Microsoft MSRC, Qualys Blog).
Microsoft released patches on December 9, 2025, as part of the December 2025 Patch Tuesday update cycle. Administrators should apply the following minimum patched build versions: Windows 10 1607/Server 2016 (10.0.14393.8688+), Windows 10 1809/Server 2019 (10.0.17763.8146+), Windows 10 21H2 (10.0.19044.6691+), Windows 10 22H2 (10.0.19045.6691+), Windows 11 23H2 (10.0.22631.6345+), Windows 11 24H2/Server 2025 (10.0.26100.7392+), Windows 11 25H2 (10.0.26200.7392+), Windows Server 2022 (10.0.20348.4467+), and Windows Server 2022 23H2 (10.0.25398.2025+). As a compensating control, organizations should enforce the principle of least privilege to limit local user account access and monitor for suspicious privilege escalation activity (Microsoft MSRC, Qualys Blog).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Bleeping Computer noted the patch release among 57 fixes in the December update, while Zero Day Initiative and Talos Intelligence published their standard monthly update reviews covering this CVE. Qualys and Sophos also included it in their Patch Tuesday analyses, with no specific researcher commentary singling out this vulnerability as particularly novel or immediately dangerous given the absence of public exploits (BleepingComputer, ZDI Blog, Talos Blog, Sophos).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."