CVE-2025-59282
Severity
7.0HIGH
EPSS
0.4%
top 40.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 14
Description
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9
Affected Packages35 packages
🔴Vulnerability Details
2CVEList▶
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability↗2025-10-14
GHSA▶
GHSA-2g3v-rq5j-m37f: Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to ex↗2025-10-14
📋Vendor Advisories
1Microsoft▶
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability↗2025-10-14