CVE-2025-24046
Published: 11 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-24046 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service. Published on March 11, 2025, it has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to its potential for significant impact on confidentiality, integrity, and availability.
The vulnerability can be exploited by an authorized local attacker with low privileges. Successful exploitation allows the attacker to elevate privileges on the affected system.
Microsoft's security advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24046 provides details on patches and mitigation guidance. Security practitioners should consult this resource for deployment instructions and apply updates promptly.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Use-after-free vulnerability in Microsoft Streaming Service allows local low-privileged attackers to elevate privileges, directly mapping to T1068 Exploitation for Privilege Escalation.