CVE-2025-59281 describes an improper link resolution vulnerability (CWE-59) in Microsoft XBox Gaming Services, allowing an authenticated local attacker to achieve privilege escalation. With a CVSS score of 7.8 (High), this vulnerability requires low attack complexity and user interaction, leading to high impacts on confidentiality, integrity, and availability. While the vulnerability has garnered some media and community attention, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's Known Exploited Vulnerabilities (KEV) catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 31.105.17001.0CPE matchmatch criteria | cpe:2.3:a:microsoft:xbox_gaming_services:*:*:*:*:*:*:*:* | ||
>= 19.0.0.0, < 31.105.17001.0CPE match | cpe:2.3:a:microsoft:xbox_gaming_services:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.