CVE-2025-24084
CVSS 3.1 Score 8.4 of 10 (high)
Details
Summary
CVE-2025-24084 is a critical vulnerability affecting Windows Subsystem for Linux (WSL). An untrusted pointer dereference in WSL allows an unauthorized attacker to execute code locally, potentially leading to serious security consequences such as data theft, privilege escalation, or system compromise. This issue can be exploited through specially crafted input, making it essential for users to apply the available patches as soon as possible to mitigate the risk. The vulnerability could be exploited even if the WSL is not enabled, highlighting the importance of maintaining all system components up-to-date.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 11
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft