PT-2025-20998 · Microsoft · Windows Win32K+1
Gábor Selján
·
Published
2025-05-13
·
Updated
2026-05-22
·
CVE-2025-30388
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Windows Win32K versions prior to the fixed version
Description:
The issue is a heap-based buffer overflow in Windows Win32K - GRFX, allowing an unauthorized attacker to execute code locally. This enables an attacker to gain SYSTEM-level access via improper memory handling. The vulnerability can be exploited by remote attackers to execute arbitrary code and affect the system.
Recommendations:
For versions prior to the fixed version, update to the latest version to resolve the issue.
As a temporary workaround, consider restricting access to the GRFX component until a patch is applied.
Avoid using the vulnerable Windows Win32K - GRFX functionality until the issue is resolved.
Fix
RCE
LPE
Heap Based Buffer Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows Win32K