CVE-2025-33052Use of Uninitialized Resource in Microsoft Windows 10 Version 1809

Severity
5.5MEDIUMNVD
EPSS
1.1%
top 22.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 10

Description

Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages17 packages

NVDmicrosoft/windows< 10.0.17763.7434+3
NVDmicrosoft/windows_10_1809< 10.0.17763.7434
NVDmicrosoft/windows_10_21h2< 10.0.19044.5965
NVDmicrosoft/windows_10_22h2< 10.0.19045.5965
NVDmicrosoft/windows_11_22h2< 10.0.22621.5472

🔴Vulnerability Details

2
GHSA
GHSA-7p8p-77rq-jh4w: Use of uninitialized resource in Windows DWM Core Library allows an authorized attacker to disclose information locally2025-06-10
CVEList
Windows DWM Core Library Information Disclosure Vulnerability2025-06-10

📋Vendor Advisories

1
Microsoft
Windows DWM Core Library Information Disclosure Vulnerability2025-06-10

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws2025-06-10
CVE-2025-33052 — Use of Uninitialized Resource | cvebase