CVE-2025-53133Use After Free in Microsoft Windows 11 Version 24h2

Severity
7.8HIGHNVD
EPSS
0.1%
top 79.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 1.1 | Impact: 6.0

Affected Packages20 packages

NVDmicrosoft/windows< 10.0.26100.4851
NVDmicrosoft/windows_11_24h2< 10.0.26100.4851
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.4946
CVEListV5microsoft/windows_11_version_24h210.0.26100.010.0.26100.4946

🔴Vulnerability Details

1
GHSA
GHSA-gchj-38gx-4pr2: Use after free in Windows PrintWorkflowUserSvc allows an authorized attacker to elevate privileges locally2025-08-12

📋Vendor Advisories

2
Microsoft
Windows PrintWorkflowUserSvc Elevation of Privilege Vulnerability2025-08-12
Microsoft
drm/amd/display: Handle dml allocation failure to avoid crash2024-12-10

🕵️Threat Intelligence

3
Bleepingcomputer
Microsoft August 2025 Patch Tuesday fixes one zero-day, 107 flaws2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review | Qualys2025-08-12
Qualys
Microsoft and Adobe Patch Tuesday, August 2025 Security Update Review2025-08-12
CVE-2025-53133 — Use After Free in Microsoft | cvebase