Junglewise Threat Intelligence

CVE-2025-24983: Microsoft Windows Win32k Use-After-Free Vulnerability

CVE-2025-24983 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2025-03-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows, Microsoft Windows Server 2012, Microsoft Windows 10 1607, Microsoft Windows Server 2016. Vendors: Microsoft.

Executive brief

A use-after-free vulnerability in the Microsoft Windows Win32 Kernel Subsystem (Win32k) allows a locally authenticated attacker to elevate privileges. The vulnerability has been observed being exploited in the wild.

Affected products

  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows 10 1507 versions prior to 10.0.10240.20947
  • Microsoft Windows 10 1607 versions prior to 10.0.14393.7876
  • Microsoft Windows Server 2016 versions prior to 10.0.14393.7876

Timeline

  • 2025-03-11: disclosed
  • 2025-03-11: patched
  • 2025-03-11: exploited: Added to CISA KEV catalog
  • 2025-03-11: kev added

Related threats