CVE-2025-59199
Published Oct 14, 2025
Last updated 7 months ago
AI description
CVE-2025-59199 is an improper access control vulnerability found within the Software Protection Platform (SPP) in Microsoft Windows. This flaw allows an authorized attacker to locally elevate their privileges. Specifically, this vulnerability, dubbed "Click Or Trick," involves a sandbox escape in Windows 11. It can be exploited by a low-integrity process to achieve escalated code execution and arbitrary file write through a chain of URI redirects and a misconfigured Component Object Model (COM) infrastructure, often requiring a single user click.
- Description
- Improper access control in Software Protection Platform (SPP) allows an authorized attacker to elevate privileges locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_10_1809, windows_10_21h2, windows_10_22h2, windows_11_22h2, windows_11_23h2, windows_11_24h2, windows_11_25h2, windows_server_2019, windows_server_2022, windows_server_2022_23h2, windows_server_2025
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-284
- nvd@nist.gov
- NVD-CWE-noinfo
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
5
Fresh @safebreach Labs research! 🔥 CVE-2025-59199 breaks down a highly creative low-integrity Windows LPE path. Learn how Notifications, COM objects, URIs, DevTools, and Windows Apps chain together in a single exploit. Great work team! 👇 https://t.co/1PgKB1WIxe
@oryair1999
2 Jun 2026
2036 Impressions
13 Retweets
25 Likes
15 Bookmarks
0 Replies
0 Quotes
🚨 Windows 11 Sandbox Escape via “toast click” (CVE-2025-59199) = Microsoft’s idea of a safe playground… with a hidden trapdoor. “Guided tour” for attackers, not users. https://t.co/w0kQY80tyP #SandboxEscape #EndpointDetection #Windows11Security #Cve202559199 https:
@windowsforum
1 Jun 2026
41 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🪟 “Click or Trick” sandbox escape (CVE-2025-59199) fixed after one-click low-to-high jump. So yeah, Windows is the attack surface again—no driver magic required. Love that for us. #Windows #Microsoft #Security https://t.co/XNMsFvKzPI #SandboxEscape #Windows11Security htt
@windowsforum
1 Jun 2026
29 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
『What makes this research unusual is that it crosses four security domains that rarely appear in the same research, let alone the same exploit.』🧐 Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs https://t.co/JcEBng9osA
@autumn_good_35
28 May 2026
346 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
New Research: Click Or Trick (CVE-2025-59199): How do you escape the Windows 11 sandbox? SafeBreach Labs uncovered that all it takes is a single user click and chaining 4 unrelated subsystems: COM, App Identity, URI quirks, and DevTools WebSockets. 🔗https://t.co/vU8r4LRg50 htt
@safebreach
28 May 2026
1139 Impressions
9 Retweets
21 Likes
8 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B51B700D-B45F-4A8E-9F78-67A1282B3BEA",
"versionEndExcluding": "10.0.17763.7919",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "1485A427-10FF-4C39-9911-4C6F1820BE7F",
"versionEndExcluding": "10.0.19044.6456",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "26CAACAA-3FE8-4740-8CF2-6BF3D069C47F",
"versionEndExcluding": "10.0.19045.6456",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6F387FA2-66C8-4B70-A537-65806271F16A",
"versionEndExcluding": "10.0.22621.6060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A3FEBF91-5010-4C84-B93A-6EFA4838185A",
"versionEndExcluding": "10.0.22631.6060",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "41E9F7AC-8E6D-43A0-A157-48A5E0B5BD0D",
"versionEndExcluding": "10.0.26100.6899",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_11_25h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "3B77A066-4F79-4B1F-AECF-58DB4C651EA5",
"versionEndExcluding": "10.0.26200.6899",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*",
"matchCriteriaId": "20810926-AEC9-4C09-9C52-B4B8FADECF3A",
"versionEndExcluding": "10.0.17763.7919",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*",
"matchCriteriaId": "B1C1EA69-6BB8-4E59-8659-43581FDB48B7",
"versionEndExcluding": "10.0.20348.4294",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:*",
"matchCriteriaId": "370C12D6-90EF-44BE-8070-AA0080C12600",
"versionEndExcluding": "10.0.25398.1913",
"vulnerable": true
},
{
"criteria": "cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*",
"matchCriteriaId": "72C1771B-635B-41E3-84AF-8822467A1869",
"versionEndExcluding": "10.0.26100.6899",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]