HIGH
CVE-2025-24983
CVSS
7
KEV
Description
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
A use-after-free vulnerability in the Windows Win32 Kernel Subsystem allows a locally authenticated attacker to manipulate freed kernel memory and elevate privileges to higher integrity levels.
Mitigation
Apply Microsoft security updates immediately upon release; this kernel-level vulnerability is patched via Windows Update. Restrict local administrative privileges and monitor for indicators of compromise.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
1.35%
Probability of exploitation in next 30 days
70.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.