CVE-2025-32709
Nullzeigerdereferenzierung in Windows Ancillary Function Driver for WinSock ermöglicht es einem autorisierten Angreifer, lokal Berechtigungen zu erhöhen.
Aktiv ausgenutzt
- Seit dem 13. Mai 2025 im CISA-Katalog ausgenutzter Schwachstellen
- US-Bundesbehörden müssen sie bis zum 3. Juni 2025 beheben (BOD 22-01)
- Angegriffen 1 Tag bevor die Schwachstelle öffentlich wurde
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Quelle: CISA KEV · 20. Jan. 2026 13. Mai 2025 13. Mai 2025 13. Mai 2025 13. Mai 2025
CVSS-Score7.8 / 10
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSchwachstellentyp (CWE)CWE-416
Herstellermicrosoft
Betroffene Produkte
| Hersteller | Produkt | Versionen |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.21014 |
| microsoft | windows 10 1607 | < 10.0.14393.8066 |
| microsoft | windows 10 1809 | < 10.0.17763.7314 |
| microsoft | windows 10 21h2 | < 10.0.19044.5854 |
| microsoft | windows 10 22h2 | < 10.0.19045.5854 |
| microsoft | windows 11 22h2 | < 10.0.22621.5335 |
| microsoft | windows 11 23h2 | < 10.0.22631.5335 |
| microsoft | windows 11 24h2 | < 10.0.26100.3981 |
| microsoft | windows server 2008 | - |
| microsoft | windows server 2012 | - |
| microsoft | windows server 2016 | < 10.0.14393.8066 |
| microsoft | windows server 2019 | < 10.0.17763.7314 |
| microsoft | windows server 2022 | < 10.0.20348.3692 |
| microsoft | windows server 2022 23h2 | < 10.0.25398.1611 |
| microsoft | windows server 2025 | < 10.0.26100.3981 |
Verwandte Artikel
This product uses the NVD API but is not endorsed or certified by the NVD.
Die technische Beschreibung ist unsere Übersetzung des englischen NVD-Originaltexts.
