Untrusted Pointer Dereference in Windows Subsystem for Linux by Microsoft
CVE-2025-24084
8.4HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 11 March 2025
Summary
A vulnerability in the Windows Subsystem for Linux allows unauthorized attackers to dereference an untrusted pointer, potentially leading to local code execution. This issue emphasizes the need for stringent security measures in the WSL environment to prevent exploitation.
Affected Version(s)
Windows 11 version 22H2 ARM64-based Systems 10.0.22621.0 < 10.0.22621.5039
Windows 11 version 22H3 ARM64-based Systems 10.0.22631.0 < 10.0.22631.5039
Windows 11 Version 23H2 x64-based Systems 10.0.22631.0 < 10.0.22631.5039
References
CVSS V3.1
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved