CVE-2025-59033
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier (such as file name or version) may not be blocked, whether hypervisor-protected code integrity (HVCI) is enabled or not. NOTE: The vendor disputes this CVE ID assignment and states that the driver blocklist is intended for use with HVCI.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.4
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.24%
- CWE
- CWE-420
- Published
- 2025-09-08
- Last modified
- 2026-03-13
Affected products
- Microsoft Windows
Weakness type
Related vulnerabilities
- CVE-2026-61909 — An issue was discovered in Cyrus IMAP before 3.12.4. CalDAV/CardDAV multiget bypasses a per-href...
- CVE-2026-77639 — Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many...
- CVE-2026-40435 — BIG-IP httpd access control vulnerability
- CVE-2026-43505 — An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when...
- CVE-2026-40217 — LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting...
- CVE-2026-35388 — OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.
- CVE-2026-25916 — Roundcube Webmail before 1.5.13 and 1.6 before 1.6.13, when "Block remote images" is used, does not...
- CVE-2025-41727 — Beckhoff: Performing privileged operations and gaining administrator access