#VU114366 Race condition in Windows Server and Microsoft Internet Information Services (IIS) - CVE-2025-55231
Published: August 22, 2025
Windows Server
Microsoft Internet Information Services (IIS)
Microsoft
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to a race condition in Windows Storage-based Management Service. A remote attacker can send specially crafted HTTP requests to the affected web server, trigger a race condition and execute arbitrary code on the system.
Note, successful exploitation of the vulnerability requires that the user restarts the affected service.