Vulnerability record · CVE-2025-24983 · published 11 March 2025
CVE-2025-24983: Windows Win32 Kernel Subsystem use-after-free privilege escalation
Microsoft · Windows 10 1507
A use-after-free flaw exists in the Windows Win32 Kernel Subsystem. A local attacker with existing credentials can trigger the memory corruption to elevate privileges on the host. Because Win32k is a core kernel component, successful exploitation gives full control of the affected system.
Description
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw is a kernel use-after-free with high confidentiality, integrity, and availability impact, and CISA lists it as actively exploited, though local access and high attack complexity temper the rating.
What it is
A use-after-free flaw exists in the Windows Win32 Kernel Subsystem. A local attacker with existing credentials can trigger the memory corruption to elevate privileges on the host. Because Win32k is a core kernel component, successful exploitation gives full control of the affected system.
Impact
An attacker who already holds a low-privileged account can escalate to SYSTEM-level privileges on the local machine. That access can be used to disable defenses, install persistence, or move laterally.
Attack surface
The vulnerability is reached locally (AV:L) and requires low privileges (PR:L) with no user interaction (UI:N). No remote or network vector is described in the record.
Exploitation
CVE-2025-24983 is listed in CISA's Known Exploited Vulnerabilities catalog with a remediation due date of 2025-04-01, indicating active exploitation in the wild. EPSS 30-day probability is 0.01348 (70th percentile), and no ransomware campaign use is documented.
What to do
- Apply the Microsoft security update referenced in the MSRC advisory for CVE-2025-24983 as soon as possible.
- Follow CISA BOD 22-01 guidance and meet the 2025-04-01 remediation deadline; discontinue use of affected products if no mitigation is available.
- Restrict local interactive logon and administrative rights to reduce the pool of accounts that can trigger the flaw.
- Monitor for and block known exploitation tooling and suspicious local privilege-escalation behavior on affected Windows hosts.
Detection
- Monitor for unexpected processes gaining SYSTEM or high-integrity tokens from low-privileged parent processes.
- Alert on unusual access to Win32k-related system calls or crashes in win32k.sys that correlate with privilege changes.
- Review Windows security event logs for anomalous token elevation or new service creation shortly after low-privileged logon.
- Track CISA KEV status and vendor advisories for updated exploitation indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-24983 to the Known Exploited Vulnerabilities catalog on 11 March 2025 as "Microsoft Windows Win32k Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 1 April 2025.
Affected products
5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24983 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24983 | US Government Resource |
Track CVE-2025-24983 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-24983), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.