CVE-2025-59033

CWE-420CWE-6933 documents3 sources
Severity
7.4HIGH
EPSS
0.0%
top 87.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 8

Description

The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may not be blocked, whether hypervisor-protected code integrity (HVCI) is enabled or not. NOTE: The vendor disputes this CVE ID assignment and states

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.4 | Impact: 5.9

Affected Packages1 packages

CVEListV5microsoft/windows10Server 2025

🔴Vulnerability Details

2
CVEList
CVE-2025-59033: The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy2025-09-08
GHSA
GHSA-h935-vxwx-xh2m: The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy2025-09-08
CVE-2025-59033 (HIGH CVSS 7.4) | The Microsoft vulnerable driver blo | cvebase.io