CVE-2025-59497Time-of-check Time-of-use (TOCTOU) Race Condition in Microsoft Defender FOR Endpoint FOR Linux

Severity
4.7MEDIUMNVD
EPSS
0.0%
top 92.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages3 packages

🔴Vulnerability Details

1
GHSA
GHSA-rc6m-rg5w-wv73: Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Linux allows an authorized attacker to deny service locally2025-10-14

📋Vendor Advisories

1
Microsoft
Microsoft Defender for Linux Denial of Service Vulnerability2025-10-14

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws2025-10-14