CVE-2025-59508

HIGH

Microsoft Windows 10 1607 < 10.0.14393.8594 - Race Condition

Title source: rule

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Speech allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 7.0
EPSS 0.0005
EPSS Percentile 14.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-362
Status published

Affected Products (14)

microsoft/windows_10_1607 < 10.0.14393.8594
microsoft/windows_10_1607 < 10.0.14393.8594
microsoft/windows_10_1809 < 10.0.17763.8027
microsoft/windows_10_1809 < 10.0.17763.8027
microsoft/windows_10_21h2 < 10.0.19044.6575
microsoft/windows_10_22h2 < 10.0.19045.6575
microsoft/windows_11_23h2 < 10.0.22631.6199
microsoft/windows_11_24h2 < 10.0.26100.7092
microsoft/windows_11_25h2 < 10.0.26200.7092
microsoft/windows_server_2016 < 10.0.14393.8594
microsoft/windows_server_2019 < 10.0.17763.8027
microsoft/windows_server_2022 < 10.0.20348.4346
microsoft/windows_server_2022_23h2 < 10.0.25398.1965
microsoft/windows_server_2025 < 10.0.26100.7092

Timeline

Published Nov 11, 2025
Tracked Since Feb 18, 2026