logo

Microsoft patches Windows Kernel zero-day exploited since 2023

ID: f833a9c2-7a02-57ea-b90d-7fae1a476741

STIX ID: report--f833a9c2-7a02-57ea-b90d-7fae1a476741

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-03-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

ESET disclosed that a use-after-free Windows kernel zero-day (CVE-2025-24983) exploited since March 2023 was used with the PipeMagic backdoor to achieve SYSTEM privileges; Microsoft patched this and five other actively exploited zero-days in March 2025, and CISA added all six to its Known Exploited Vulnerabilities Catalog with a federal remediation deadline.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.