CNNVD-202508-1186 Information

CNNVD ID

CNNVD-202508-1186

CVE-2025-50168

  • CNNVD Published: 2025-08-12

Description (Chinese)

Microsoft Win32k是美国微软(Microsoft)公司的一个用于Windows多用户管理的系统文件。 Microsoft Win32K - ICOMP存在安全漏洞。攻击者利用该漏洞可以提升权限。以下产品和版本受到影响:Windows Server 2022, 23H2 Edition (Server Core installation),Windows 11 Version 24H2 for ARM64-based Systems,Windows 11 Version 24H2 for x64-based Systems,Windows Server 2025,Windows 11 Version 22H2 for ARM64-based Systems,Windows 11 Version 22H2 for x64-based Systems,Windows Server 2025 (Server Core installation),Windows 11 Version 23H2 for ARM64-based Systems,Windows 11 Version 23H2 for x64-based Systems。

Description (English)

Microsoft Win32k is a system file for Windows multi-user management by Microsoft United States. Microsoft Win32K-ICOMP has a security breach. The attackers use this loophole to enhance their authority. The following products and versions are affected: Windows Server 2022, 23H2 Evaluation (Server Corporation), Windows 11 Version 24H2 for ARM 64-based Systems, Windows 11 Version 24H2 for x 64-based Systems, Windows Server 2025, Windows 22H2 for ARM64-based Systems, Windows 11Version 23H2 for ARM 64-systems, Windows 11 Views 22H2 for x64-based Systems, Windows 23H2 for 23H64-based Systems.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

微软

Published

2025-08-12

Last Modified

2026-02-24

References

https://nvd.nist.gov/vuln/detail/CVE-2025-50168 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50168

Patch

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50168

Share on: