CVE-2025-24983
Microsoft · Published March 11, 2025
7.0
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 10 1507 < 10.0.10240.20947
- Windows 10 1607 < 10.0.14393.7876
- Windows Server 2008
- Windows Server 2012
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H