CVE-2025-24983
KEVmassWindows Win32k Use-After-Free Privilege Escalation Zero-Day (CVE-2025-24983)
CISA: Microsoft Windows Win32k Use-After-Free Vulnerability
CVE-2025-24983 is a use-after-free memory-safety flaw (CWE-416) in the Windows Win32 kernel (Win32k) subsystem that allows an attacker who already has limited local access on a Windows machine to elevate privileges; it requires low privileges and no user interaction but carries high attack complexity (CVSS 3.1: 7.0). Because it is a local elevation-of-privilege bug rather than remote code execution, it is typically used to deepen control after an initial foothold, and the high attack complexity makes exploitation less turnkey than typical Win32k EoP bugs. Microsoft shipped fixes among 57 March 2025 Patch Tuesday updates on March 11, 2025, flagging this as one of six actively exploited zero-days, and CISA added it to the Known Exploited Vulnerabilities catalog the same day (ransomware use: unknown). Anyone running the affected legacy releases — Windows 10 1507 and 1607 and Windows Server 2008, 2012, and 2016 — without the March 2025 updates is exposed, especially environments where multiple or less-trusted users can log on locally. No public proof-of-concept is known and EPSS puts the 30-day exploitation probability at about 1.3%; note that same-cycle headlines about a Windows zero-day exploited in ransomware attacks on US real estate firms (PipeMagic trojan) cover the March Patch Tuesday zero-days without the provided data confirming that CVE-2025-24983 specifically was the one used in those ransomware attacks.
What to do: Apply the March 2025 Patch Tuesday security updates (released March 11, 2025) to every affected Windows 10 1507/1607 and Windows Server 2008/2012/2016 host, since in-the-wild exploitation is confirmed and no public PoC or workaround details are available. Prioritize systems where untrusted or semi-trusted users can log on locally, and confirm compliance with CISA BOD 22-01 requirements for federal systems. After patching, hunt for signs of prior compromise (unexpected local administrator activity, suspicious service or task creation) because an EoP bug of this type is usually exercised after an initial foothold.
| Microsoft Windows 10 1507 | Windows 10 version 1507 (original release) — all builds prior to the March 2025 Patch Tuesday security updates |
| Microsoft Windows 10 1607 | Windows 10 version 1607 — all builds prior to the March 2025 Patch Tuesday security updates |
| Microsoft Windows Server 2008 | Windows Server 2008 — all builds prior to the March 2025 Patch Tuesday security updates |
| Microsoft Windows Server 2012 | Windows Server 2012 — all builds prior to the March 2025 Patch Tuesday security updates |
| Microsoft Windows Server 2016 | Windows Server 2016 — all builds prior to the March 2025 Patch Tuesday security updates |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Win32 Kernel Subsystem allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H