Microsoft has disclosed a critical remote code execution vulnerability in its Internet Information Services (IIS) platform . The security flaw puts organizations that rely on Windows servers for web hosting at risk.

The vulnerability, codenamed CVE-2025-59282, affects the handling of Inbox COM Objects in memory, resulting from a race condition and use-after-free error. It was announced on October 14, 2025 and has a CVSS 3.1 score of 7.0 (rated as “Important” by Microsoft).
Although it has not yet been exploited, security experts warn that the potential for arbitrary code execution could allow attackers to compromise the integrity of the server, steal data, or conduct broader network attacks. The vulnerability occurs during concurrent execution, where shared resources are not properly synchronized, allowing an unauthorized attacker to manipulate memory states.
See also: New flaw in SAP NetWeaver allows server takeover
According to the CVE details, the exploit requires local access, but can come from a remote adversary, who tricks a user into opening a malicious file. No privileges are required, although the high complexity of the attack requires achieving a precise race condition. This makes the exploit challenging but feasible for capable malicious actors.
At its core, CVE-2025-59282 exploits weaknesses in CWE-362 (race condition) and CWE-416 (use-after-free) in IIS's handling of COM objects. When a user interacts with a crafted file, such as a specially crafted document or script, the vulnerability causes improper memory handling. This leads to a use-after-free scenario, where freed memory is accessed simultaneously, allowing code injection.
The CVSS vector string, CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H, highlights key factors: local attack, high complexity, user interaction required, and high impact on confidentiality, integrity, and availability. Microsoft clarifies that the word “remote” in the title refers to the location of the attacker, not the location of execution.
See also: Veeam Backup: Critical RCE vulnerabilities allow remote code execution

No proof-of-concept code has been released, but researchers note similarities to previous memory issues in IIS. In that case, attackers were able to escalate privileges to the SYSTEM level. Affected versions include Windows Server versions with IIS enabled, although Microsoft has not specified exact versions.
Successful exploitation could allow attackers to execute arbitrary code with the privileges of the IIS process, which often runs as SYSTEM on misconfigured servers.
In enterprise environments, this could expose sensitive web applications, databases, or API endpoints to ransomware deployment, data extraction , or lateral movement. For example, a compromised IIS server on a corporate intranet could act as an entry point for advanced threats targeting the financial or healthcare sectors.
Given the “Exploitation Unlikely” rating from Microsoft’s MSRC, the immediate threat remains low. However, the lack of patches at the time of disclosure requires immediate action. No indicators of compromise (IoCs) have been determined yet, but monitoring for unusual COM object interactions or memory anomalies in IIS logs is recommended
See also: Vulnerability in FortiPAM and FortiSwitch Manager bypasses verification process

Microsoft ISS Vulnerability: Defense
The simplest defense is to disable IIS when not in use, as unaffected systems are not at risk. Microsoft recommends applying upcoming patches via Windows Update and restricting file execution policies. Enabling User Account Control (UAC) and logging COM interactions can further strengthen defenses.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Security researchers emphasize early patching to prevent escalation. As IIS powers millions of web servers, this vulnerability highlights the need for careful memory-safe coding in legacy components. Organizations should scan environments and review web server configurations immediately.
