Oct 2025: Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
CVE-2025-58731 Published on October 14, 2025
Inbox COM Objects (Global Memory) Remote Code Execution Vulnerability
Use after free in Inbox COM Objects allows an unauthorized attacker to execute code locally.
Weakness Type
What is a Dangling pointer Vulnerability?
Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.
CVE-2025-58731 has been classified to as a Dangling pointer vulnerability or weakness.
Products Associated with CVE-2025-58731
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 11 version 22H2:- Version 10.0.22621.0 and below 10.0.22621.6060 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6060 is affected.
- Version 10.0.22631.0 and below 10.0.22631.6060 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
- Version 10.0.26200.0 and below 10.0.26200.6899 is affected.
- Version 10.0.20348.0 and below 10.0.20348.4294 is affected.
- Version 10.0.25398.0 and below 10.0.25398.1913 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
- Version 10.0.26100.0 and below 10.0.26100.6899 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.