You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-55224
About this tag
CVE-2025-55224 is a high-priority local elevation-of-privilege vulnerability in the Windows kernel graphics component (Win32K GRFX). It is caused by a race condition due to improper synchronization, which an authorized local attacker can exploit to gain code execution or elevate privileges. This flaw poses significant risk for multi-user hosts, RDP/VDI endpoints, and systems processing untrusted graphical content. Microsoft has released a security advisory and patch guidance for CVE-2025-55224, emphasizing the need for prompt remediation on affected Windows systems.
Microsoft’s advisory for CVE-2025-55224 describes a concurrency flaw in the Windows kernel graphics component (Win32K — GRFX) that can be manipulated by an authorized local actor to gain code execution or elevate privileges on an affected system; the bug is a race condition (improper...