CVE-2025-60708: Storvsp.sys Driver Denial of Service Vulnerability

Overview

Severity
Medium (CVSS 6.5)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H/E:U/RL:O/RC:C
Category
Denial of Service
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2025-Nov
Released
2025-11-11
EPSS Score
0.04% (percentile: 13.0%)

Description

Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.

FAQ

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability? In this case, a successful attack could be performed from a low privilege Hyper-V guest. The attacker could traverse the guest's security boundary to cause denial of service on the Hyper-V host environment.

Affected Products (19)

Windows

  • Windows 10 Version 1809 for x64-based Systems
  • Windows Server 2019
  • Windows Server 2019 (Server Core installation)
  • Windows Server 2022
  • Windows Server 2022 (Server Core installation)
  • Windows 10 Version 21H2 for x64-based Systems
  • Windows Server 2025 (Server Core installation)
  • Windows 11 Version 25H2 for ARM64-based Systems
  • Windows 11 Version 25H2 for x64-based Systems
  • Windows 11 Version 23H2 for ARM64-based Systems
  • Windows 11 Version 23H2 for x64-based Systems
  • Windows Server 2022, 23H2 Edition (Server Core installation)
  • Windows 11 Version 24H2 for ARM64-based Systems
  • Windows 11 Version 24H2 for x64-based Systems
  • Windows Server 2025
  • Windows 10 Version 1607 for x64-based Systems
  • Windows Server 2016
  • Windows Server 2016 (Server Core installation)

ESU

  • Windows 10 Version 22H2 for x64-based Systems

Security Updates (9)

Acknowledgments

Valter Wik with <a href="https://cparta.se/">Cparta Cyber Defense AB</a>, Valter Mann with <a href="https://cparta.se/">Cparta Cyber Defense AB</a>

Revision History

  • 2025-11-11: Information published.