CVE-2025-24046

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 416

Summary

CVE-2025-24046 is a newly discovered vulnerability in Microsoft Streaming Service. This issue permits an attacker who already has authorized access to the system to potentially elevate their privileges through a use-after-free condition. This type of vulnerability occurs when memory that has been allocated but is no longer in use is referenced, allowing an attacker to manipulate the software and gain elevated access. Microsoft is actively working on a patch to address this vulnerability, and users are encouraged to apply it as soon as it becomes available to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share