CVE-2025-24983CISA KEV
Microsoft Windows Win32k Use-After-Free Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- Product
- Windows
- Added to KEV
- 11 Mar 2025
- Federal remediation due
- 1 Apr 2025
- Known ransomware use
- Not reported