CVE-2025-24983
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
- Affected products
- Windows
- Microsoft Windows 10 1507
- < 10.0.10240.20947
- Microsoft Windows 10 1607
- < 10.0.14393.7876
- Microsoft Windows Server 2008
- All versions
- Microsoft Windows Server 2012
- All versions
- Microsoft Windows Server 2016
- < 10.0.14393.7876
- CVSS 3.1
- 7.0 HIGH
- EPSS
- 1.3% (69th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2025-03-11
CVE-2025-24983 at NVD
1 known exploit for CVE-2025-24983
Proof-of-concept code and exploit modules indexed by Sploitus