CVE-2025-59195

Severity
7.0HIGH
EPSS
0.0%
top 91.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attacker to deny service locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages21 packages

NVDmicrosoft/windows< 10.0.17763.7919+3
NVDmicrosoft/windows_10_1809< 10.0.17763.7919
NVDmicrosoft/windows_10_21h2< 10.0.19044.6456
NVDmicrosoft/windows_10_22h2< 10.0.19045.6456
NVDmicrosoft/windows_11_22h2< 10.0.22621.6060

🔴Vulnerability Details

2
CVEList
Windows Graphics Component Denial of Service Vulnerability2025-10-14
GHSA
GHSA-pxxf-v3rf-8rpq: Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Graphics Component allows an authorized attac2025-10-14

📋Vendor Advisories

1
Microsoft
Windows Graphics Component Denial of Service Vulnerability2025-10-14
CVE-2025-59195 (HIGH CVSS 7) | Concurrent execution using shared r | cvebase.io