CVE-2025-59194

HIGH

Windows 11 22H2-25H2 and Windows Server 2022 23H2/2025 - Privilege Escalation via Uninitialized Resource

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-59194. PoCs published by kawaii-ghost.

AI-analyzed exploit summary The repository contains a minimal IoRing API demonstration in C++ that initializes an IoRing and sets up a read operation. It lacks exploit-specific logic or payload execution, suggesting it is a stub or incomplete PoC for CVE-2025-59194.

Description

Use of uninitialized resource in Windows Kernel allows an authorized attacker to elevate privileges locally.

Exploits (1)

nomisec STUB
by kawaii-ghost · poc
https://github.com/kawaii-ghost/CVE-2025-59194

The repository contains a minimal IoRing API demonstration in C++ that initializes an IoRing and sets up a read operation. It lacks exploit-specific logic or payload execution, suggesting it is a stub or incomplete PoC for CVE-2025-59194.

Classification
Stub 80%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Windows IoRing API (version unspecified)
No auth needed
Prerequisites: Windows system with IoRing API support
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.0
EPSS 0.0244
EPSS Percentile 82.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-908
Status published
Products (6)
microsoft/windows_11_22h2 < 10.0.22621.6060
microsoft/windows_11_23h2 < 10.0.22631.6060
microsoft/windows_11_24h2 < 10.0.26100.6899
microsoft/windows_11_25h2 < 10.0.26200.6899
microsoft/windows_server_2022_23h2 < 10.0.25398.1913
microsoft/windows_server_2025 < 10.0.26100.6899
Published Oct 14, 2025
Tracked Since Feb 18, 2026