PT-2025-42143 · Microsoft · Xbox Gaming Services

Published

2025-10-14

·

Updated

2025-10-17

·

CVE-2025-59281

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xbox Gaming Services (affected versions not specified)
Description An issue involving improper link resolution before file access, known as 'link following', exists in Xbox Gaming Services. This allows an authorized attacker to elevate privileges locally. The flaw enables local privilege escalation through symlink attacks and is considered trivial to weaponize.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Link Following

Weakness Enumeration

Related Identifiers

CVE-2025-59281

Affected Products

Xbox Gaming Services