cbcvebase.
CVE-2025-24983
published 2025-03-11

CVE-2025-24983: Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

PriorityP184high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2025-04-01
Exploited in the wild
EPSS
1.30%
67.2th percentile
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.

Affected

22 ranges
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_1607< 10.0.14393.787610.0.14393.7876
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.276186.1.7601.27618
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.231686.0.6003.23168
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.253686.2.9200.25368
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.224706.3.9600.22470
microsoftwindows_server_2016< 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
msrcwindows_10_for_32-bit_systems
msrcwindows_10_for_x64-based_systems
msrcwindows_10_version_1607_for_32-bit_systems
msrcwindows_10_version_1607_for_x64-based_systems
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2025-24983 is a use-after-free in the Windows Win32 Kernel Subsystem exploited in the wild; monitor for local privilege escalation to SYSTEM via a race condition in Win32k.
  • Exploitation requires winning a race condition; hunt for repeated rapid Win32k syscall patterns indicative of race-condition exploitation attempts.
  • Successful exploitation grants SYSTEM privileges; alert on unexpected SYSTEM-level process creation from non-SYSTEM parent processes on Windows endpoints.
  • Exploitation has been observed in targeted cyber espionage campaigns; treat detections of CVE-2025-24983 exploitation as high-severity targeted intrusion events.
  • CVE-2025-24983 exploitation status is confirmed in the wild; prioritize patching and monitor exploit detection telemetry on all affected Windows versions.
  • ·Windows 11 version 24H2 systems are not affected by the observed exploitation even though the vulnerability is present in the codebase.
  • ·Patches for Windows 10 LTSB 2015 were delayed at time of reporting; systems running that version may remain unpatched and should be treated as higher risk.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.