Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
Microsoft
CVE-2025-59280 CVSS 3.1
2025-10-14 07:00 UTC · 2025-10-14 04:00 -03
Improper authentication in Windows SMB Client allows an unauthorized attacker to perform tampering over a network.
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Hyper-V allows an authorized attacker to elevate privileges locally.
Improper access control in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Improper access control in Windows SMB Server allows an authorized attacker to elevate privileges over a network.