CVE-2025-24048
Published: 11 March 2025
Description
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Security Summary
CVE-2025-24048 is a heap-based buffer overflow vulnerability in the Windows Hyper-V role, published on 2025-03-11T17:16:26.703. It carries a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and maps to CWE-122 (Heap-based Buffer Overflow) and CWE-125 (Out-of-bounds Read).
A local attacker with low privileges (PR:L) can exploit this vulnerability with low attack complexity and no user interaction required. Successful exploitation allows privilege escalation, enabling high impacts on confidentiality, integrity, and availability.
Mitigation details are available in the Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24048.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
Heap-based buffer overflow in Hyper-V enables local privilege escalation via vulnerability exploitation.