CVE-2025-24036

CVSS 3.1 Score 7 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 14, 2025
CWE ID 367

Summary

CVE-2025-24036 is an elevation of privilege vulnerability affecting Microsoft AutoUpdate (MAU). attackers who successfully exploit this weakness can gain higher system privileges on Windows systems. MAU is a component responsible for installing and updating Microsoft software. The flaw could be exploited through a specially crafted MAU package, enabling attackers to escalate their user-level privileges to administrator-level access. Microsoft has released a patch to address this vulnerability, and users are advised to update their systems promptly to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft AutoUpdate

Affected Vendors

  • Microsoft