CVE-2025-24064
Published: 11 March 2025
Description
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Security Summary
CVE-2025-24064 is a use-after-free vulnerability (CWE-416) affecting the DNS Server component. Published on 2025-03-11, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H). The flaw enables an unauthorized attacker to execute code over a network.
An unauthorized network attacker with no required privileges or user interaction can exploit this vulnerability. Due to the high attack complexity, successful exploitation allows remote code execution with high impacts on confidentiality, integrity, and availability.
The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24064 provides details on patches and mitigation guidance.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise Techniques
Why these techniques?
The use-after-free vulnerability in the DNS Server component allows unauthenticated remote code execution over the network (AV:N), directly enabling T1190 (Exploit Public-Facing Application) as the primary attack vector for initial access and code execution on the exposed service.