CVE-2025-24988: Windows USB Video Class System Driver Elevation of Privilege Vulnerability
Out-of-bounds read in Windows USB Video Driver allows an authorized attacker to elevate privileges with a physical attack.
Other sources
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24988?
CVE-2025-24988 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2025-24988?
To mitigate CVE-2025-24988, apply the appropriate security updates provided by Microsoft for your affected Windows version.
Which systems are affected by CVE-2025-24988?
CVE-2025-24988 affects several Microsoft Windows systems including Windows Server 2012 R2, Windows 10, Windows 11, and Windows Server 2022.
What type of attack does CVE-2025-24988 enable?
CVE-2025-24988 enables an authorized attacker to perform privilege escalation through a physical attack.
Is there a patch available for CVE-2025-24988?
Yes, Microsoft has released patches to address CVE-2025-24988 for affected Windows systems.