Описание
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-59282
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59282
- https://www.vicarius.io/vsociety/posts/cve-2025-59282-detection-script-race-condition-in-microsoft-inbox-com-objects
- https://www.vicarius.io/vsociety/posts/cve-2025-59282-mitigation-script-race-condition-in-microsoft-inbox-com-objects
Связанные уязвимости
CVSS3: 7
nvd
10 месяцев назад
Concurrent execution using shared resource with improper synchronization ('race condition') in Inbox COM Objects allows an unauthorized attacker to execute code locally.
CVSS3: 7
msrc
10 месяцев назад
Internet Information Services (IIS) Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVSS3: 7
fstec
10 месяцев назад
Уязвимость компонента Internet Information Services операционных систем Windows, позволяющая нарушителю выполнить произвольный код