CVE-2025-24987: Windows USB Video Class System Driver Elevation of Privilege Vulnerability
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
Other sources
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24987?
CVE-2025-24987 is classified as a critical vulnerability that allows privilege escalation via an out-of-bounds read in the Windows USB Video Driver.
How do I fix CVE-2025-24987?
To fix CVE-2025-24987, apply the latest security patches provided by Microsoft for your affected Windows version.
Which Microsoft products are affected by CVE-2025-24987?
CVE-2025-24987 affects multiple Microsoft products, including Windows 10, Windows 11, and various versions of Windows Server.
Can an attacker exploit CVE-2025-24987 remotely?
No, CVE-2025-24987 requires a physical attack to exploit, as it involves privilege escalation through a local device.
Is there a workaround for CVE-2025-24987 until I can apply a patch?
Currently, the recommended action is to update the affected systems with the provided patches as there are no effective workarounds.