CyberICT

CVE-2025-59281

Microsoft · Published October 14, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Xbox Gaming Services Elevation of Privilege Vulnerability. Improper link resolution before file access ('link following') in XBox Gaming Services allows an authorized attacker to elevate privileges locally.

Affected Products

  • Xbox Gaming Services

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C