CVE-2025-27732CWE-591

Windows Graphics Component Elevation of Privilege Vulnerability

High · published April 8, 2025

CVSS v3.1
7.0
EPSS
0%
Percentile
27.0
In the wild
Unconfirmed
What it is

Sensitive data storage in improperly locked memory in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
CVSS v4.0
Not supplied
EPSS
0.00341 · 27.0th percentile
Weakness
CWE-591 · Sensitive Data Storage in Improperly Locked Memory
Published
2025-04-08T17:24Z
EPSS history
Timeline
  • 08 APR 17:24Z
    Windows Graphics Component Elevation of Privilege Vulnerability
    cvelistv5