CVE-2025-24043 is a high-severity vulnerability affecting Microsoft WinDbg, where improper cryptographic signature verification in .NET allows an authenticated attacker to achieve remote code execution over a network. With a CVSS score of 7.5, this vulnerability has high impact on confidentiality, integrity, and availability, but requires high attack complexity. There is no evidence of active exploitation, nor are public exploits available, though it has received some community discussion and media coverage as part of Microsoft's March 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2502.25002.0CPE matchmatch criteria | cpe:2.3:a:microsoft:windbg:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.2502.25002.0CPE match | cpe:2.3:a:microsoft:windbg:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.