CVE-2025-24997
published 2025-03-11CVE-2025-24997: Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
PriorityP416medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.55%
41.4th percentile
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_21h2 | < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_22h2 | < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_11_22h2 | < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_23h2 | < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_24h2 | < 10.0.26100.3403 | 10.0.26100.3403 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3476 | 10.0.26100.3476 |
| microsoft | windows_server_2022 | < 10.0.20348.3270 | 10.0.20348.3270 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3328 | 10.0.20348.3328 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1486 | 10.0.25398.1486 |
| microsoft | windows_server_2025 | < 10.0.26100.3403 | 10.0.26100.3403 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.3476 | 10.0.26100.3476 |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_arm64-based_systems | — | — |
| msrc | windows_11_version_22h2_for_x64-based_systems | — | — |
| msrc | windows_11_version_23h2_for_arm64-based_systems | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
vendor_msrc4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44vj-x828-cfmj: Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally
ghsa_unreviewed·2025-03-11
CVE-2025-24997 [MEDIUM] CWE-476 GHSA-44vj-x828-cfmj: Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally
Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
Microsoft
DirectX Graphics Kernel File Denial of Service Vulnerability
vendor_msrc·2025-03-11·CVSS 4.4
CVE-2025-24997 [MEDIUM] CWE-476 DirectX Graphics Kernel File Denial of Service Vulnerability
DirectX Graphics Kernel File Denial of Service Vulnerability
Description: Null pointer dereference in Windows Kernel Memory allows an authorized attacker to deny service locally.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to compromise admin credentials on the device.
Windows Kernel Memory: Windows Kernel Memory
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Denial of Service
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5053603
Reference: https://support.microsoft.com/help/5053603
Reference: https://support
No detection rules found.
No public exploits indexed.
2025-03-11
Published