CVE-2025-24983
CVSS 3.1 Score 7 of 10 (high)
Details
Published Mar 11, 2025
Updated: Mar 13, 2025
CWE ID 416
Summary
CVE-2025-24983 is a newly disclosed vulnerability affecting the Windows Win32 Kernel Subsystem. This issue allows an attacker who has already gained authorized access to the system to elevate their privileges further by exploiting a use-after-free condition. Once exploited, the attacker can execute arbitrary code with elevated privileges, potentially leading to significant security compromises. This vulnerability poses a serious risk to systems running affected versions of Windows and requires immediate attention for patching and mitigation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.