CVE-2025-24044
Published: 11 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-24044 is a use-after-free vulnerability (CWE-416) in the Windows Win32 Kernel Subsystem. It affects Windows systems and was published on 2025-03-11T17:16:26.093 with a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
An authorized local attacker with low privileges can exploit this vulnerability to elevate privileges. The attack vector is local with low attack complexity and no user interaction required, potentially resulting in high impacts to confidentiality, integrity, and availability.
The Microsoft Security Response Center provides an update guide with details on mitigation and patches at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24044.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Local use-after-free vulnerability in Windows kernel subsystem enabling privilege escalation from low-privileged local attacker.