CVE CVE

CVE-2025-24983

CISA Known Exploited Vulnerability (KEV)

Microsoft Windows Win32k Use-After-Free Vulnerability

March 11, 2025

April 1, 2025

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Weakness Enumeration

CWE-ID CWE Name

CWE-416
Use After Free

Details

Source:
NVD
Published:
Updated:

Risk information

CVSS v3

Base score:
7
Severity:

HIGH

Vector:
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2

Not defined