HIGH

CVE-2025-24983

Microsoft Windows 10 1507 2025-03-11 CVSS v3.1
CVSS
7
KEV

Description

Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

A use-after-free vulnerability in the Windows Win32 Kernel Subsystem allows a locally authenticated attacker to manipulate freed kernel memory and elevate privileges to higher integrity levels.

Mitigation

Apply Microsoft security updates immediately upon release; this kernel-level vulnerability is patched via Windows Update. Restrict local administrative privileges and monitor for indicators of compromise.

Patch Commit

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

1.35%
Probability of exploitation in next 30 days
70.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE