CVE-2025-24995

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 122

Summary

CVE-2025-24995 is a critical vulnerability affecting the Kernel Streaming WOW Thunk Service Driver. This issue involves a heap-based buffer overflow, which can be exploited by an attacker who has already gained authorized access to the system. Successful exploitation allows the attacker to elevate privileges, giving them higher levels of system control and potential access to sensitive data or system functions. This vulnerability poses a significant risk to security and requires immediate attention and patching to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share