VDB
GCVE-110-NCSC-2025-358
GCVE-110-NCSC-2025-358
Advisory PublishedCVSS 7.8/10
The document highlights a vulnerability in Windows Administrator Protection that allows an authorized attacker to locally escalate privileges due to an untrusted search path issue.
Weaknesses (CWE)
CWE-415Double FreeCWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CWE-201Insertion of Sensitive Information Into Sent DataCWE-59Improper Link Resolution Before File Access ('Link Following')CWE-73External Control of File Name or PathCWE-284Improper Access ControlCWE-125Out-of-bounds ReadCWE-822Untrusted Pointer DereferenceCWE-325Missing Cryptographic StepCWE-416Use After FreeCWE-269Improper Privilege ManagementCWE-122Heap-based Buffer OverflowCWE-126Buffer Over-readCWE-532Insertion of Sensitive Information into Log FileCWE-426Untrusted Search PathCWE-270Privilege Context Switching Error
Risk Scores
CVSS 3.1
7.8/10
High · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Microsoft | vers:unknown/* | — | — |
Aliases
CVE-2025-59505CVE-2025-59506CVE-2025-59507CVE-2025-59508CVE-2025-59509CVE-2025-59510CVE-2025-59511CVE-2025-59512CVE-2025-59513CVE-2025-59514CVE-2025-59515CVE-2025-60703CVE-2025-60704CVE-2025-60705CVE-2025-60706CVE-2025-60707CVE-2025-60708CVE-2025-60709CVE-2025-60710CVE-2025-60713CVE-2025-60714CVE-2025-60715CVE-2025-60716CVE-2025-60717CVE-2025-60718CVE-2025-60719CVE-2025-60720CVE-2025-60721CVE-2025-60723CVE-2025-60724CVE-2025-62208CVE-2025-62209CVE-2025-62213CVE-2025-62215CVE-2025-62217CVE-2025-62218CVE-2025-62219CVE-2025-62452
References
Browse GCVE Records
74,585 records in the GCVE database · Updated July 24, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.