Race Condition Vulnerability in Windows Win32K - GRFX
CVE-2025-55224

7.8HIGH

What is CVE-2025-55224?

A race condition vulnerability in the Windows Win32K - GRFX component allows an authorized attacker to execute arbitrary code on affected systems. This occurs due to improper synchronization in concurrent executions leveraging shared resources. Attackers may exploit this weakness locally, potentially leading to unauthorized actions within the operating system.

Affected Version(s)

Windows 10 Version 1809 x64-based Systems 10.0.17763.0 < 10.0.17763.7792

Windows 10 Version 21H2 x64-based Systems 10.0.19044.0 < 10.0.19044.6332

Windows 10 Version 22H2 x64-based Systems 10.0.19045.0 < 10.0.19045.6332

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-55224 : Race Condition Vulnerability in Windows Win32K - GRFX