Improper Validation of Specified Type of Input
CVE-2025-59277
Summary
Improper validation of specified type of input in Windows Authentication Methods allows an authorized attacker to elevate privileges locally.
- LOW
- LOCAL
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-1287 - Improper Validation of Specified Type of Input
The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.
References
Advisory Timeline
- Published