Microsoft has recorded CVE-2025-58725 as a local elevation-of-privilege vulnerability in the Windows COM+ Event System (an inbox COM service), where a heap-based buffer overflow can allow an authorized local attacker to escalate to higher privileges on affected hosts.
Background / Overview
The...
Microsoft has recorded CVE-2025-58725 as an elevation-of-privilege vulnerability in the Windows COM+ Event System (Inbox COM) / COM-based handler family that can allow a locally authorized attacker to escalate privileges on affected Windows hosts; administrators should treat this as a...
com heap overflow
compluseventsystem
cve 2025 58725
cve-2025-58725
elevation of privilege
eop vulnerability
inbox com
local privilege escalation
patch management
privilege escalation
windows security